{"id":390,"date":"2013-04-26T22:17:36","date_gmt":"2013-04-27T05:17:36","guid":{"rendered":"http:\/\/seanmurphree.com\/blog\/?p=390"},"modified":"2013-04-26T22:17:36","modified_gmt":"2013-04-27T05:17:36","slug":"damo-web-security-challenge-i","status":"publish","type":"post","link":"https:\/\/seanmurphree.com\/blog\/?p=390","title":{"rendered":"Damo Web Security Challenge I"},"content":{"rendered":"<p>Today we&#8217;re going to be looking at another web based wargame. \u00a0The wargame we&#8217;ll look at is the first level of the Damo Web Security Challenges. \u00a0These challenges can be found at the damo site <a href=\"http:\/\/damo.clanteam.com\/\" target=\"_blank\">here<\/a>. \u00a0To get started, head over the the first challenge page <a href=\"http:\/\/damo.clanteam.com\/sch1\/index.php\" target=\"_blank\">here<\/a>.<a href=\"http:\/\/damo.clanteam.com\/\"><br \/>\n<\/a><\/p>\n<p>Reading the page, we can see there is a Hall of Fame page which we are supposed to put our name on. \u00a0There is also a link with the text &#8216;admin&#8217;. \u00a0If we click on the admin link, we get prompted for a username\/password in a fashion that looks like .htaccess\/.htpasswd. \u00a0Next, if we click on the Hall of Fame link, we can see it makes use of index.php?page=halloffame. \u00a0This should signify that a page is included based on the page variable, something we can leverage.<\/p>\n<p>To leverage, let&#8217;s try to read the .htaccess and .htpasswd files for the admin directory. To do so, lets change the url to index.php?page=admin\/.htaccess \u00a0Once we do, we see an error. \u00a0This error shows us the the page is trying to include &#8220;admin\/.htaccess.php&#8221;. \u00a0Since we didn&#8217;t add the .php, we can assume it&#8217;s added by the script. \u00a0To get around that, we can add %00 (NULL) to the end of the URL, which will cause the subsequent calls which evaluate the page variable to stop reading the string when the null is reached. \u00a0Upon loading the page again with the null appended to the end of the URL we see the entry of .htaccess for the admin directory. \u00a0This entry refers to the .htpasswd file to be used for the directory. \u00a0If we go look at it, we should be able to get a username\/password to crack. \u00a0So let&#8217;s redirect our URL again to index.php?page=..\/hiddenfoldersch1\/.htpasswd%00<\/p>\n<p>The page now shows the entry in the .htpasswd file; A username and password for the admin directory. \u00a0However, the password still needs to be cracked. \u00a0So, let&#8217;s put the password into John The Ripper. \u00a0After a few seconds, the password is cracked and a username and password combo are ready to be used to access the admin directory.<\/p>\n<p>Now we can enter the username\/password on the admin directory and add our name to the Hall of Fame. \u00a0Hooray!<\/p>\n<p>So What?<\/p>\n<p>Includes are risky, at worst one should white list them, at best, don&#8217;t directly do includes on user supplied data. \u00a0Watch out for null bytes prematurely terminating user supplied strings. \u00a0Use strong passwords and hashing algorithms.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today we&#8217;re going to be looking at another web based wargame. \u00a0The wargame we&#8217;ll look at is the first level of the Damo Web Security Challenges. \u00a0These challenges can be found at the damo site here. \u00a0To get started, head &hellip; <a href=\"https:\/\/seanmurphree.com\/blog\/?p=390\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[4],"tags":[],"_links":{"self":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/390"}],"collection":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=390"}],"version-history":[{"count":3,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/390\/revisions"}],"predecessor-version":[{"id":393,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/390\/revisions\/393"}],"wp:attachment":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}