{"id":32,"date":"2012-07-19T22:15:36","date_gmt":"2012-07-20T05:15:36","guid":{"rendered":"http:\/\/seanmurphree.com\/blog\/?p=32"},"modified":"2012-07-19T22:52:43","modified_gmt":"2012-07-20T05:52:43","slug":"blowfish-level1","status":"publish","type":"post","link":"https:\/\/seanmurphree.com\/blog\/?p=32","title":{"rendered":"Blowfish Level1"},"content":{"rendered":"<p>Welcome back for another posting at Technolution. \u00a0Please remember the final password for today&#8217;s game will be stripped on this page and replaced with Y&#8217;s. \u00a0If you want to do the level, go do it. \u00a0Now, onto the games! \u00a0Today we&#8217;re going to be starting a new wargame on the <a title=\"Smash The Stack Network\" href=\"http:\/\/www.smashthestack.org\" target=\"_blank\">SmashTheStack Network<\/a>, Blowfish! \u00a0You can find information about the Blowfish wargame on it&#8217;s main page, <a title=\"here\" href=\"http:\/\/blowfish.smashthestack.org:81\/\" target=\"_blank\">here<\/a>. \u00a0Reading up, this game already seems a little different in the way level 1 works. \u00a0Instead of ssh&#8217;ing in right away, we&#8217;re supposed to telnet to port 6666 of blowfish.smashthestack.org. \u00a0Upon connecting, an encrypted password will be sent to us for level 2. \u00a0However, as it is encrypted, we will have to decrypt it before we can use it to ssh into blowfish as level2.<\/p>\n<p>Today I&#8217;m working from Windows, so we&#8217;ll be using PuTTy to get the password. \u00a0Open Putty, choose telnet (since there is a protocol difference) and specify port 6666 on blowfish.smashthestack.org. \u00a0Before connecting, choose to never close window on exit. \u00a0We do this since the server closes the connection after sending the string and we need the window to stay open long enough for us to read the string ourselves. \u00a0Once you&#8217;re setup, go a head and connect. \u00a0Upon connecting we should get the following text:<\/p>\n<blockquote><p>$1$4JKI4bjj$EucGdPgVb6uc4oTUQ.mJV0<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>Crack this passwd with john the ripper<br \/>\nand use the password to login with<br \/>\nssh level2@blowfish.smashthestack.org -p 2222<\/p>\n<p>&#8211; <a title=\"http:\/\/iamyas.blogspot.com\/2008\/01\/format-of-etcshadow-file.html\" href=\"http:\/\/iamyas.blogspot.com\/2008\/01\/format-of-etcshadow-file.html\" target=\"_blank\">http:\/\/iamyas.blogspot.com\/2008\/01\/format-of-etcshadow-file.html<\/a><br \/>\n&#8211; <a title=\"http:\/\/www.openwall.com\/john\/\" href=\"http:\/\/www.openwall.com\/john\/\" target=\"_blank\">http:\/\/www.openwall.com\/john\/<\/a><\/p><\/blockquote>\n<p>Ok, that&#8217;s straight forward. \u00a0If you haven&#8217;t used john the ripper before, go download it from the above link. \u00a0John is a password cracking utility. \u00a0In this case we&#8217;re going to be cracking a md5 password hash from \/etc\/shadow. \u00a0John cracks password files and thus the password hashes have to be in the correct format. \u00a0Simply make a password.txt file (name doesn&#8217;t matter) in the john\\run directory (with the john.exe file). \u00a0Lines in the password.txt file should be for the format:<\/p>\n<blockquote><p>username:password:last_password_change:min_days:max_days:warning:inactive:expired_date<\/p><\/blockquote>\n<p>That&#8217;s a long list, but for what we are doing the only important fields are the username:password fields. \u00a0To make use, let&#8217;s put the following in our password.txt file.<\/p>\n<blockquote><p>level2:$1$4JKI4bjj$EucGdPgVb6uc4oTUQ.mJV0:::::::<\/p><\/blockquote>\n<p>Next, load a command prompt and change your current directory to wherever your john.exe file is. \u00a0From here we will use the dictionary list supplied by john, password.lst, to attempt to guess the password used for level2. \u00a0(The password that when encrypted by md5, gives the md5 hash we received above.) \u00a0To do this we use the follow command, and get the following results!<\/p>\n<blockquote><p>c:\\&#8230;\\john179\\run&gt; john &#8211;wordlist=password.lst passwd.txt<br \/>\nLoaded 1 password hash (FreeBSD MD5 [32\/32])<br \/>\nYYYYYYY (level2)<br \/>\nguesses: 1 time: 0:00:00:00 100% c\/s: 9533 trying: YYYYYYY<\/p><\/blockquote>\n<p>Tada! \u00a0Here we are. \u00a0John found the password that when encrypted with MD5, gives the same password hash as we had for username level2. \u00a0Now we can take that password and -following the instructions we received at the beginning of the level- ssh to port 2222 on blowfish.smashthestack.org and log in as level2\/YYYYYYY.<\/p>\n<p>In today&#8217;s example we used a wordlist. \u00a0That means that if the original password (in this case &#8220;YYYYYYY&#8221;) wasn&#8217;t in password.lst, then we would never have gotten the password. \u00a0This can be maneuvered around by using a brute force attack, and hopefully we&#8217;ll see something like that in a later level. \u00a0Brute force attacks end up trying all possible character combinations (given a specific character set) and thus don&#8217;t require lists. \u00a0However, for long enough passwords, brute forcing can take prohibitively long to get a password in the worst, or even average, case scenario. \u00a0(If you&#8217;re interested in brute force cracking and how long things are taking in 2011, I&#8217;d recommend watching the <a title=\"Economics of Password Cracking in the GPU Era\" href=\"http:\/\/www.youtube.com\/watch?v=HYw5Vcx2BdY\" target=\"_blank\">Economics of Password Cracking in the GPU Era<\/a> talk from Defcon19, by Robert &#8220;Hackajar&#8221; Imhoff-Dousharm of SanDisk Corporation.)<\/p>\n<p>Anyway, we&#8217;ll stop there for today. \u00a0Please check back later for the next level of Blowfish, as well as other wargames and postings!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome back for another posting at Technolution. \u00a0Please remember the final password for today&#8217;s game will be stripped on this page and replaced with Y&#8217;s. \u00a0If you want to do the level, go do it. \u00a0Now, onto the games! \u00a0Today &hellip; <a href=\"https:\/\/seanmurphree.com\/blog\/?p=32\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[16,6,4],"tags":[17,51,19,20,18,49,47],"_links":{"self":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/32"}],"collection":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=32"}],"version-history":[{"count":10,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/32\/revisions"}],"predecessor-version":[{"id":36,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/32\/revisions\/36"}],"wp:attachment":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=32"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=32"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=32"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}