Google CTF 2016: Ernst Echidna

John Hammond · Intermediate ·📰 AI News & Updates ·10y ago

Key Takeaways

The video discusses the Google CTF 2016 challenge Ernst Echidna, presented by John Hammond, covering AI and cybersecurity topics, specifically focusing on Capture The Flag challenges and problem-solving strategies.

Full Transcript

Hey, what's going on everybody? My name is John Hammond and in this video I wanted to bring to you uh one of the easiest solutions to some of the Google capture the flag CTF that uh got started this weekend. It was going on from I think April 29th to May 1st I think. Uh it was their first annual Google CTF. So a lot of people seemed like they were jumping in on it and I was one of them. The challenge I wanted to show you is Ernst Akidna. It was only worth 50 points. wasn't really a big challenge and a lot of people solved it. 737 people were able to get this one. So, it's pretty simple challenge, but I want to just walk you through it and build a a quick get flag script for you. So, uh here we go. Can you hack this website? The robots.ext sure looks interesting. Hm. Okay, let's take a look at this. And uh it says, "Welcome to Strawberry T. Access to the is restricted." Okay. Please register to get access. Whatever. Uh let's check out that robots.ext text that they were hinting at. Robots.ext. And it does not want us to go to the admin page. Okay. Well, what is over there? Let's check that one out. For/admin. And it tells us, oh, we're not logged in. Fine. I guess we will uh go back and now try and log in and register. Okay. So, if we can register for account, it's just it's pretty simple username and password field. There's nothing interesting in here. If you take a look at the source, there's nothing hidden. There's nothing hidden in the old page. There's it's just plain straight HTML. So if we register, I guess we'll just do some stuff. Uh I don't know just to fill stuff out. Let's go for the purpose of explanation. A and B as our username and password. We're registered. Thank you for registering. Unfortunately, there's no content. That's fine. Can we get to our admin page now? That's really all we care about, right? Okay. Sorry. This interface is restricted to administrators only. Well, dang, that's annoying. Thank you for registering. Unfortunately, there's been no content posted on the site. Okay. How's it keeping track of the fact that I am registered and logged in? That's probably done with a cookie, right? So, I mean, you can uh view cookies in Firefox with like cookie manager. It's a cool plugin. Uh if you don't already have it, I totally recommend you grab it because I'm going to use that to take a look at what we have here. I'm going to fire up cookie manager as the actual tool, not the Google search. My bad. And we want to be looking at our website. Ernst Akidna is a challenge that we're looking at right now. And it has a cookie. It has a cookie set for us. MD5 hash looks like, right? Hopefully you guys can see this. I'm sorry if it's too small. I can't really zoom in on this. Okay. So, it's MD5 hash cookie has a value that I'm assuming just based off its name is an MD5 hash. Um, now MD5 is pretty much well known for being pretty weak. So, I wonder if we can hack it. I wonder if we can crack that or find a collision for this uh MD5 hash. So, I just Googled MD5 cracker and md5cracker.org was a good one that I ended up using. Um, so I threw my hash in there and whoa, a lot of people told me that it has the result of just simple A. And that's what we just put in as our username. You see, you remember when we lo when we registered as A as our username and B as our password. So, it looked like all it really did was MD5 hash our username. So, can we have it kind of fool can we fool the web page into thinking that I am the administrator? Let's delete our current cookie. I'll just remove that. Now, if I go to the page, looks like I have to register. Can I log in? Can I register as admin? Okay. Admin account already taken. Oh, well. Okay. Dang. But what's to stop us from like changing our changing our cookie already that we already have? So, if we fire up cookie manager one more time, our MD5 hash, which is currently the MD5 hash of the letter A, our username. Let's actually create our own MD5 hash of the word admin of that admin user. And can we just set this to be it right? Can we set this to be our cookie? Do I have uh All right, I still have it. I still have it up. Good. Let's go into cookie manager. Change the value of our MD5 hash cookie to now the MD5 hash of the the username admin. Save it. Refresh the page. There's nothing new here. But now if I go to admin, hey, that admin page now lets us come on in. And it says, "Hey, congratulations. your token is this flag. Cool. So, we just got the flag, right? We would be we would be able to submit this, but uh some of you guys may know I don't really like just leaving it at that. I'd like to be able to script this or automate getting the flag for us. So, let's go ahead and start to build something that will let us do that. Fire up Sublime Text. Get a new script going. I guess in Google CTF I have a I'll just create a get flag.py script for us. I'll try and zoom in here so you can see it. Get a shebang line going. Let's import re um I'm sorry, a request. And let's import hashlib. So we'll actually use that to MD5 stuff. We'll say username equals admin because that's what we want. MD5 can equal hashlib.m MD5 just to create our MD5 object. Um so MD5.update with username and then um MD5 I guess hash which is what we'll set the value of the cookie can be equal to that MD5 objects hex digest. So once it actually gets the digest of this uh username admin and once it hashes the word admin MD5 hash now we see okay we've successfully hashed MD5 now let's actually make that call let's get a request object open we can just say s equals request session scookies if we if I were to show you that currently it is just an empty cookie jar let's actually update that I'll remove this print statement with a new dictionary for the string MD5 hash. Set it to our MD5 hash that we've actually is actually the hash. Now, if we were to print out S.Cookies, you should be able to see, oh, okay, cool. MD5 hash is actually a cookie in there. That's just fine. So, now we should be able to run s.get on our admin page. If we try and run this and print it out, it does have an error because we need to verify the SSL certificate. I'm going to ignore that. So, we can do that with uh verify equals false. Probably not the best idea, but it does get to what we wanted to. It gets a response to 100. So, let's save that as R. We can print out R.ext. Here we go. Okay, cool. Congratulations. Your token is. And let's just scrape that out with regular expressions. Um, content can equal that. And then what is it that we're trying to find? Re dot re.arch. All right. Matched equals re.arch. Pattern will be CTF. Anything in here. And let's escape these out. And we'll find that in our contents. So, if matched, print matched. What do we get here? Nothing. I might not need to have these. Um, congratulations. your token to CTF. That should totally work. Do I need to like escape my uh asterisk here too? Here. I'll pause this so I can get it right for you. Sorry, guys. All right, I'm dumb. I completely forgot about the fact that I just actually needed to put the inside of the flag like in parenthesis or the actual like whole thing. Okay, my fail. So, yeah, CTF and then the flag format is this curly braces and you can just denote that, hey, I actually want this as part of a found group. So, if I just left it. Okay, now it should work. Cool. Very nice. Uh I don't know how I can hide that uh security warning. Let's do some research and find that. Again, I'm kind of going off off the cuff right now. I probably shouldn't be doing this much research and like doing things that I don't have scripted or at least I don't have prepared, but requests ignore warning. Python requests ignore insecure requests warning. Is there a way to suppress that? Looks like there's just this line. Okay, sure. Stole that off the internet. No big deal. Copy and paste. Copy paste code off stack overflow. That's good. That's good programming practice, right? That's funny. Okay. Sure. Real simple thing just to uh get flag uh let's make this executable. See Google Earns executable chmod plus x get flag.py. Okay. And that that gets our flag for us. Sweet. We're done. I'm I I spent too much time on this problem trying to show you something very very simple, but it was a lot of fun. So, thanks guys. Hope you enjoyed this real simple uh part of Google CTF. Really, really cool CTF. I didn't get a whole lot of challenges, but it was a ton of fun. So, thanks again, guys. See you in a next later video.

Original Description

If you would like to support me, please like, comment & subscribe, and check me out on Patreon: https://patreon.com/johnhammond010 E-mail: johnhammond010@gmail.com PayPal: http://paypal.me/johnhammond010 GitHub: https://github.com/JohnHammond Site: http://www.johnhammond.org Twitter: https://twitter.com/_johnhammond
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from John Hammond · John Hammond · 28 of 60

1 Code Commentaries? PHP to JavaScript in Bash and PHP!
Code Commentaries? PHP to JavaScript in Bash and PHP!
John Hammond
2 Tutorials? MySQL connection with PHP and Bash!
Tutorials? MySQL connection with PHP and Bash!
John Hammond
3 Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
Variable Naming in Python! Happy Birthday, Linux! Nokia N900!
John Hammond
4 JavaScript Splits The URL!
JavaScript Splits The URL!
John Hammond
5 HTML Tables in Python!
HTML Tables in Python!
John Hammond
6 HTML, Net Shares, GML!
HTML, Net Shares, GML!
John Hammond
7 Python 08 Programming Style and Comments
Python 08 Programming Style and Comments
John Hammond
8 Python 26 Object Oriented Programming
Python 26 Object Oriented Programming
John Hammond
9 75 Python Tutorials, Out Now!
75 Python Tutorials, Out Now!
John Hammond
10 Batch 14 Mathematical Expressions
Batch 14 Mathematical Expressions
John Hammond
11 Batch 85 Array Append
Batch 85 Array Append
John Hammond
12 Batch 86 Array Count
Batch 86 Array Count
John Hammond
13 Batch 87 Array Index
Batch 87 Array Index
John Hammond
14 Batch 88 Array Insert
Batch 88 Array Insert
John Hammond
15 Batch 89 Array Remove
Batch 89 Array Remove
John Hammond
16 Batch 90 Array Reverse
Batch 90 Array Reverse
John Hammond
17 Python [colorama] 00 Installing on Linux
Python [colorama] 00 Installing on Linux
John Hammond
18 Python [colorama] 09 Cursor Position
Python [colorama] 09 Cursor Position
John Hammond
19 Python [hashlib] 02 Algorithms
Python [hashlib] 02 Algorithms
John Hammond
20 Python 00 Installing IDLE on Linux
Python 00 Installing IDLE on Linux
John Hammond
21 Python [pygame] 11 Rectangular Collision Detection
Python [pygame] 11 Rectangular Collision Detection
John Hammond
22 Python [pygame] 12 Platforming Rectangular Collision Resolution
Python [pygame] 12 Platforming Rectangular Collision Resolution
John Hammond
23 Python [XML-RPC] 01 Research
Python [XML-RPC] 01 Research
John Hammond
24 Python [pyenchant] 03 Personal Word Lists
Python [pyenchant] 03 Personal Word Lists
John Hammond
25 FancyURLopener Authentication and User-Agent [urllib] 03
FancyURLopener Authentication and User-Agent [urllib] 03
John Hammond
26 Python 04: PEP8 Coding
Python 04: PEP8 Coding
John Hammond
27 Python Challenge! 17 COOKIES
Python Challenge! 17 COOKIES
John Hammond
Google CTF 2016: Ernst Echidna
Google CTF 2016: Ernst Echidna
John Hammond
29 Google CTF 2016: Spotted Quoll
Google CTF 2016: Spotted Quoll
John Hammond
30 Google CTF 2016: Can you Repo It?
Google CTF 2016: Can you Repo It?
John Hammond
31 Google CTF 2016: No Big Deal
Google CTF 2016: No Big Deal
John Hammond
32 Google CTF 2016: In Recorded Conversation
Google CTF 2016: In Recorded Conversation
John Hammond
33 Homemade CTF Challenge: 01 "Orchestra"
Homemade CTF Challenge: 01 "Orchestra"
John Hammond
34 Homemade CTF Challenge: 02 "Bae's Base"
Homemade CTF Challenge: 02 "Bae's Base"
John Hammond
35 Homemade CTF Challenge: 03 "Web Hunt"
Homemade CTF Challenge: 03 "Web Hunt"
John Hammond
36 Homemade CTF Challenge: 04 "UPX"
Homemade CTF Challenge: 04 "UPX"
John Hammond
37 Homemade CTF Challenge: 05 "The Assumption Song"
Homemade CTF Challenge: 05 "The Assumption Song"
John Hammond
38 Homemade CTF Challenge: 06 "A Brisk Stroll"
Homemade CTF Challenge: 06 "A Brisk Stroll"
John Hammond
39 Homemade CTF Challenge: 06 "I lost my password!"
Homemade CTF Challenge: 06 "I lost my password!"
John Hammond
40 web25 :: Mr. Robot : EKOPARTY CTF 2016
web25 :: Mr. Robot : EKOPARTY CTF 2016
John Hammond
41 web50 : RFC 7230 :: EKOPARTY CTF 2016
web50 : RFC 7230 :: EKOPARTY CTF 2016
John Hammond
42 misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
misc50 : Hidden inside EKO :: EKOPARTY CTF 2016
John Hammond
43 Hack The Vote 2016 CTF: Sander's Fan Club [web100]
Hack The Vote 2016 CTF: Sander's Fan Club [web100]
John Hammond
44 Hack The Vote 2016 CTF Warpspeed [forensics150]
Hack The Vote 2016 CTF Warpspeed [forensics150]
John Hammond
45 Juniors CTF 2016 :: Black Suprematic Square
Juniors CTF 2016 :: Black Suprematic Square
John Hammond
46 Juniors CTF 2016 :: Six Strange Tales
Juniors CTF 2016 :: Six Strange Tales
John Hammond
47 Juniors CTF 2016 :: Lost Code
Juniors CTF 2016 :: Lost Code
John Hammond
48 Juniors CTF 2016 :: Here Goes!
Juniors CTF 2016 :: Here Goes!
John Hammond
49 Juniors CTF 2016 :: Southern Cross
Juniors CTF 2016 :: Southern Cross
John Hammond
50 Juniors CTF 2016 :: Clone Attack
Juniors CTF 2016 :: Clone Attack
John Hammond
51 Juniors CTF 2016 :: Dirty Repo
Juniors CTF 2016 :: Dirty Repo
John Hammond
52 Juniors CTF 2016 :: Hackers Blog
Juniors CTF 2016 :: Hackers Blog
John Hammond
53 Juniors CTF 2016 :: Voting!!!
Juniors CTF 2016 :: Voting!!!
John Hammond
54 Juniors CTF 2016 :: The Good, The Bad and The Junkman
Juniors CTF 2016 :: The Good, The Bad and The Junkman
John Hammond
55 Juniors CTF 2016 :: Stop Thief!
Juniors CTF 2016 :: Stop Thief!
John Hammond
56 Juniors CTF 2016 :: ROFL
Juniors CTF 2016 :: ROFL
John Hammond
57 Juniors CTF 2016 :: Restriced Area
Juniors CTF 2016 :: Restriced Area
John Hammond
58 Juniors CTF 2016 :: Oh SSH!
Juniors CTF 2016 :: Oh SSH!
John Hammond
59 HackCon CTF 2017 TRIVIA and BONUS Challenges
HackCon CTF 2017 TRIVIA and BONUS Challenges
John Hammond
60 HackCon CTF 2017 "Bacche" Challenges
HackCon CTF 2017 "Bacche" Challenges
John Hammond

The video discusses the Google CTF 2016 challenge Ernst Echidna, covering problem-solving strategies and cybersecurity topics. Viewers can learn how to approach CTF challenges and apply AI concepts to solve complex problems.

Key Takeaways
  1. Watch the video to understand the Ernst Echidna challenge
  2. Analyze the problem-solving strategies presented
  3. Apply the strategies to solve similar CTF challenges
  4. Stay updated on AI news and cybersecurity topics
💡 The video provides valuable insights into problem-solving strategies and cybersecurity topics, highlighting the importance of staying updated on AI news and applying AI concepts to solve complex problems.

Related Reads

📰
The Half-Life 2 of AI isn't a smarter chatbot
Don't assume AI is behind every impressive tech feat, as human innovation can still surpass expectations
Dev.to AI
📰
AI in Journalism: The One Writing the News Is No Longer a Reporter
AI is being used in journalism to generate news content, changing the way news is written and consumed
Medium · AI
📰
Why Cursor’s Change-of-Control Clause Became the Model Deadline
Learn how OpenAI's deadline for Cursor models was set after SpaceX's Anysphere deal, and its implications for AI development
Medium · Programming
📰
5 Leadership Behaviors Separating Companies That Win With AI From Companies Just Using It
Discover the 5 leadership behaviors that distinguish companies successfully leveraging AI from those just using it, and learn how to apply these behaviors to drive business success
Medium · AI
Up next
The Surprising Downfall of Google
Matthew Berman
Watch →