SlideShare a Scribd company logo
1 of 24
Download to read offline
PHDays CTF 2014 Final
Max Moroz
June 07, 2014
whoami
Max Moroz
 Captain
 Job: C++, Objective-C, Java
 Freelance: pentesting
 Interests: crypto, forensic, misc
BalalaikaCr3w
./teaminfo
which CTF
which CTF
which CTF
which CTF
cat rules.txt
• Ubuntu 14.04
• services:
– cardbook (:1234)
= 12 × 3
– mobol (:3123)
= 24 × 2
– holynet (:80)
= 48 × 1
#PREPARE TO BATTLE
./tribute –to=SecurityFirst
• tcpdump –A port 80 | grep ‘w{32}’ | nc $VODKA
• tcpdump –A port 1234 | grep ‘w{32}’| nc $VODKA
• tcpdump –A port 3123 | grep ‘w{32}’ | nc $VODKA
#P0WN3R ACHIEVEMENT UNLOCKED
DEBUG:root:new game!
DEBUG:root:suits in game: ['S', 'D', 'C', 'H', 'E', 'A', 'T', 'Z']
DEBUG:root:received cards: set(['2ofE', 'AofD', '6ofA', 'KofH', '3ofA', '10ofT', '5ofH', '4ofH', '9ofH', '6ofS',
'AofT', 'AofZ', 'JofC', 'QofH', '3ofT', '4ofD', '8ofC'])
DEBUG:root:state is 0, hand is 2ofE AofD 6ofA KofH 3ofA 10ofT 5ofH 4ofH 9ofH 6ofS AofT AofZ JofC
QofH 3ofT 4ofD 8ofC
DEBUG:root:Received: INFO: players in this session: [0, 2, 4, 5, 6, 7]
<…>
DEBUG:root:Received: TRICK SUCCEEDED
DEBUG:root:state is 0, hand is
DEBUG:root:Received: INFO: new round
DEBUG:root:state is 0, hand is
DEBUG:root:Received: END. WIN! Take your prizes: b1bbee3e61d9dbd2b808b9d6efc55ac6
2f00f06026cdabe99c09725431b84064 4ba4c7f5f44563c73be0a436f0474a4f
ae2c9ce87ddafa1d8eb715eee6e61f4f c62c93363e933111a4dd502477b8d386
3dbf50201f9bc2e5b4d7d2f268b2e868 1f958958cead352be5810b49ca5ca378
8ba6516044e9926822a6dc85bdee591f e762d36f93384a29140f70c73d45e398
655cfa6d598710475734e50212d6ef5a
DEBUG:root:game ended, I won
./cardbook
• tail –f cardbook-stderr.log | grep ‘w{32}’ | nc $VODKA
./mobol
./exploit_mobol –thanks-to=bay
./holynet
./exploit_holynet
VODKA
FLAGS STATISTICS:
Flags found: 4426
Successfully sent: 1249
Waiting for resend: 85
Bad flags: 0
All Flags
Submitted
./vodka --stat
cat game_economics.txt
Task Name Reward (gold) Price (Power) Price (Armor) Price (Fuel)
crackme 1000 15 0 0
breadcrumbs 2500 12 16 1
musicforsoul 2500 15 4 6
mars2 2000 22 6 0
holygrail 2000 13 2 5
homepage 2500 4 8 8
doubleshizo 3000 0 21 5
oracle2 5000 19 27 6
mooditter 5000 64 5 2
pyhtonisback 1000 14 1 0
tera 2000 4 9 7
packIt9000 5000 4 7 21
Wolfram|ɛπτα 2000 18 5 2
lockpicking 2000 15 5 3
my favorite sequel 4000 8 22 7
schoolmath 2000 1 14 3
Total 43500 228 152 76
Gold from selling 3648 3648 3648
cat game_economics.txt
Task Name Reward (gold) Price (Power) Price (Armor) Price (Fuel)
crackme 1000 15 0 0
breadcrumbs 2500 12 16 1
musicforsoul 2500 15 4 6
mars2 2000 22 6 0
holygrail 2000 13 2 5
homepage 2500 4 8 8
doubleshizo 3000 0 21 5
oracle2 5000 19 27 6
mooditter 5000 64 5 2
pyhtonisback 1000 14 1 0
tera 2000 4 9 7
packIt9000 5000 4 7 21
Wolfram|ɛπτα 2000 18 5 2
lockpicking 2000 15 5 3
my favorite sequel 4000 8 22 7
schoolmath 2000 1 14 3
Total 43500 228 152 76
Gold from selling 3648 3648 3648
./WASTED
cat game_economics.txt
Task Name Reward (gold) Price (Power) Price (Armor) Price (Fuel)
crackme 1000 15 0 0
breadcrumbs 2500 12 16 1
musicforsoul 2500 15 4 6
mars2 2000 22 6 0
holygrail 2000 13 2 5
homepage 2500 4 8 8
doubleshizo 3000 0 21 5
oracle2 5000 19 27 6
mooditter 5000 64 5 2
pyhtonisback 1000 14 1 0
tera 2000 4 9 7
packIt9000 5000 4 7 21
Wolfram|ɛπτα 2000 18 5 2
lockpicking 2000 15 5 3
my favorite sequel 4000 8 22 7
schoolmath 2000 1 14 3
Total 43500 228 152 76
Gold from selling 3648 3648 3648
./balance
echo $SCOREBOARD
sudo halt
@dor3s
max.moroz.1337
http://ctfcrew.org
balalaikacr3w@gmail.com

More Related Content

Similar to PHDays CTF 2014 Final Write-Up

Descriptive analytics in r programming language
Descriptive analytics in r programming languageDescriptive analytics in r programming language
Descriptive analytics in r programming languageAshwini Mathur
 
Владимир Кириллов-TCP-Performance for-Mobile-Applications
Владимир Кириллов-TCP-Performance for-Mobile-ApplicationsВладимир Кириллов-TCP-Performance for-Mobile-Applications
Владимир Кириллов-TCP-Performance for-Mobile-ApplicationsUA Mobile
 
Проблемы использования TCP в мобильных приложениях. Владимир Кириллов
Проблемы использования TCP в мобильных приложениях.  Владимир КирилловПроблемы использования TCP в мобильных приложениях.  Владимир Кириллов
Проблемы использования TCP в мобильных приложениях. Владимир КирилловAnthony Marchenko
 
Debugging Ruby Systems
Debugging Ruby SystemsDebugging Ruby Systems
Debugging Ruby SystemsEngine Yard
 
Kernelvm 201312-dlmopen
Kernelvm 201312-dlmopenKernelvm 201312-dlmopen
Kernelvm 201312-dlmopenHajime Tazaki
 
How To Crack RSA Netrek Binary Verification System
How To Crack RSA Netrek Binary Verification SystemHow To Crack RSA Netrek Binary Verification System
How To Crack RSA Netrek Binary Verification SystemJay Corrales
 
Get your moneys worth out of your database
Get your moneys worth out of your databaseGet your moneys worth out of your database
Get your moneys worth out of your databasePatrick Barel
 
Precomputed Voxelized-Shadows for Large-scale Scene and Many lights
Precomputed Voxelized-Shadows for Large-scale Scene and Many lightsPrecomputed Voxelized-Shadows for Large-scale Scene and Many lights
Precomputed Voxelized-Shadows for Large-scale Scene and Many lightsSeongdae Kim
 
Ethereum 9¾ @ Devcon5
Ethereum 9¾ @ Devcon5Ethereum 9¾ @ Devcon5
Ethereum 9¾ @ Devcon5Wanseob Lim
 
쉐도우맵을 압축하여 대규모씬에 라이팅을 적용해보자
쉐도우맵을 압축하여 대규모씬에 라이팅을 적용해보자쉐도우맵을 압축하여 대규모씬에 라이팅을 적용해보자
쉐도우맵을 압축하여 대규모씬에 라이팅을 적용해보자Seongdae Kim
 
what engineers don't know (but probably mathematicians do)
what engineers don't know (but probably mathematicians do)what engineers don't know (but probably mathematicians do)
what engineers don't know (but probably mathematicians do)budi rahardjo
 
Using Deep Learning (Computer Vision) to Search for Oil and Gas
Using Deep Learning (Computer Vision) to Search for Oil and GasUsing Deep Learning (Computer Vision) to Search for Oil and Gas
Using Deep Learning (Computer Vision) to Search for Oil and GasSorin Peste
 
NoSQL Containers get Rich
NoSQL Containers get RichNoSQL Containers get Rich
NoSQL Containers get RichStefano Valle
 
GPU/VGA Thermal Design Power
GPU/VGA Thermal Design PowerGPU/VGA Thermal Design Power
GPU/VGA Thermal Design PowerDen Ronggo
 
Cassandra : to be or not to be @ TechTalk
Cassandra : to be or not to be @ TechTalkCassandra : to be or not to be @ TechTalk
Cassandra : to be or not to be @ TechTalkAndriy Rymar
 
Building a Cost-effective Mining Rig by Michael Carter (BitsBeTrippin)
Building a Cost-effective Mining Rig by Michael Carter (BitsBeTrippin)Building a Cost-effective Mining Rig by Michael Carter (BitsBeTrippin)
Building a Cost-effective Mining Rig by Michael Carter (BitsBeTrippin)Hashers United
 
Scaling the #2ndhalf
Scaling the #2ndhalfScaling the #2ndhalf
Scaling the #2ndhalfSalo Shp
 

Similar to PHDays CTF 2014 Final Write-Up (20)

Descriptive analytics in r programming language
Descriptive analytics in r programming languageDescriptive analytics in r programming language
Descriptive analytics in r programming language
 
Владимир Кириллов-TCP-Performance for-Mobile-Applications
Владимир Кириллов-TCP-Performance for-Mobile-ApplicationsВладимир Кириллов-TCP-Performance for-Mobile-Applications
Владимир Кириллов-TCP-Performance for-Mobile-Applications
 
Проблемы использования TCP в мобильных приложениях. Владимир Кириллов
Проблемы использования TCP в мобильных приложениях.  Владимир КирилловПроблемы использования TCP в мобильных приложениях.  Владимир Кириллов
Проблемы использования TCP в мобильных приложениях. Владимир Кириллов
 
Debugging Ruby Systems
Debugging Ruby SystemsDebugging Ruby Systems
Debugging Ruby Systems
 
IDS.pptx
IDS.pptxIDS.pptx
IDS.pptx
 
Kernelvm 201312-dlmopen
Kernelvm 201312-dlmopenKernelvm 201312-dlmopen
Kernelvm 201312-dlmopen
 
League of Graphs
League of GraphsLeague of Graphs
League of Graphs
 
How To Crack RSA Netrek Binary Verification System
How To Crack RSA Netrek Binary Verification SystemHow To Crack RSA Netrek Binary Verification System
How To Crack RSA Netrek Binary Verification System
 
Get your moneys worth out of your database
Get your moneys worth out of your databaseGet your moneys worth out of your database
Get your moneys worth out of your database
 
Precomputed Voxelized-Shadows for Large-scale Scene and Many lights
Precomputed Voxelized-Shadows for Large-scale Scene and Many lightsPrecomputed Voxelized-Shadows for Large-scale Scene and Many lights
Precomputed Voxelized-Shadows for Large-scale Scene and Many lights
 
Ethereum 9¾ @ Devcon5
Ethereum 9¾ @ Devcon5Ethereum 9¾ @ Devcon5
Ethereum 9¾ @ Devcon5
 
쉐도우맵을 압축하여 대규모씬에 라이팅을 적용해보자
쉐도우맵을 압축하여 대규모씬에 라이팅을 적용해보자쉐도우맵을 압축하여 대규모씬에 라이팅을 적용해보자
쉐도우맵을 압축하여 대규모씬에 라이팅을 적용해보자
 
what engineers don't know (but probably mathematicians do)
what engineers don't know (but probably mathematicians do)what engineers don't know (but probably mathematicians do)
what engineers don't know (but probably mathematicians do)
 
Using Deep Learning (Computer Vision) to Search for Oil and Gas
Using Deep Learning (Computer Vision) to Search for Oil and GasUsing Deep Learning (Computer Vision) to Search for Oil and Gas
Using Deep Learning (Computer Vision) to Search for Oil and Gas
 
NoSQL Containers get Rich
NoSQL Containers get RichNoSQL Containers get Rich
NoSQL Containers get Rich
 
GPU/VGA Thermal Design Power
GPU/VGA Thermal Design PowerGPU/VGA Thermal Design Power
GPU/VGA Thermal Design Power
 
Cassandra : to be or not to be @ TechTalk
Cassandra : to be or not to be @ TechTalkCassandra : to be or not to be @ TechTalk
Cassandra : to be or not to be @ TechTalk
 
4900514.ppt
4900514.ppt4900514.ppt
4900514.ppt
 
Building a Cost-effective Mining Rig by Michael Carter (BitsBeTrippin)
Building a Cost-effective Mining Rig by Michael Carter (BitsBeTrippin)Building a Cost-effective Mining Rig by Michael Carter (BitsBeTrippin)
Building a Cost-effective Mining Rig by Michael Carter (BitsBeTrippin)
 
Scaling the #2ndhalf
Scaling the #2ndhalfScaling the #2ndhalf
Scaling the #2ndhalf
 

More from defconmoscow

7.5. Pwnie express IRL
7.5. Pwnie express IRL7.5. Pwnie express IRL
7.5. Pwnie express IRLdefconmoscow
 
7.4. Show impact [bug bounties]
7.4. Show impact [bug bounties]7.4. Show impact [bug bounties]
7.4. Show impact [bug bounties]defconmoscow
 
7.3. iCloud keychain-2
7.3. iCloud keychain-27.3. iCloud keychain-2
7.3. iCloud keychain-2defconmoscow
 
7.2. Alternative sharepoint hacking
7.2. Alternative sharepoint hacking7.2. Alternative sharepoint hacking
7.2. Alternative sharepoint hackingdefconmoscow
 
7.1. SDLC try me to implenment
7.1. SDLC try me to implenment7.1. SDLC try me to implenment
7.1. SDLC try me to implenmentdefconmoscow
 
6.3. How to get out of an inprivacy jail
6.3. How to get out of an inprivacy jail6.3. How to get out of an inprivacy jail
6.3. How to get out of an inprivacy jaildefconmoscow
 
6.2. Hacking most popular websites
6.2. Hacking most popular websites6.2. Hacking most popular websites
6.2. Hacking most popular websitesdefconmoscow
 
6.1. iCloud keychain and iOS 7 data protection
6.1. iCloud keychain and iOS 7 data protection6.1. iCloud keychain and iOS 7 data protection
6.1. iCloud keychain and iOS 7 data protectiondefconmoscow
 
6. [Bonus] DCM MI6
6. [Bonus] DCM MI66. [Bonus] DCM MI6
6. [Bonus] DCM MI6defconmoscow
 
5.3. Undercover communications
5.3. Undercover communications5.3. Undercover communications
5.3. Undercover communicationsdefconmoscow
 
5.2. Digital forensics
5.2. Digital forensics5.2. Digital forensics
5.2. Digital forensicsdefconmoscow
 
5.1. Flashback [hacking AD]
5.1. Flashback [hacking AD]5.1. Flashback [hacking AD]
5.1. Flashback [hacking AD]defconmoscow
 
5. [Daily hack] Truecrypt
5. [Daily hack] Truecrypt5. [Daily hack] Truecrypt
5. [Daily hack] Truecryptdefconmoscow
 
4.5. Contests [extras]
4.5. Contests [extras]4.5. Contests [extras]
4.5. Contests [extras]defconmoscow
 
4.4. Hashcracking server on generic hardware
4.4. Hashcracking server on generic hardware4.4. Hashcracking server on generic hardware
4.4. Hashcracking server on generic hardwaredefconmoscow
 
4.3. Rat races conditions
4.3. Rat races conditions4.3. Rat races conditions
4.3. Rat races conditionsdefconmoscow
 
4.2. Web analyst fiddler
4.2. Web analyst fiddler4.2. Web analyst fiddler
4.2. Web analyst fiddlerdefconmoscow
 
4.1. Path traversal post_exploitation
4.1. Path traversal post_exploitation4.1. Path traversal post_exploitation
4.1. Path traversal post_exploitationdefconmoscow
 
3.3. Database honeypot
3.3. Database honeypot3.3. Database honeypot
3.3. Database honeypotdefconmoscow
 

More from defconmoscow (20)

7.5. Pwnie express IRL
7.5. Pwnie express IRL7.5. Pwnie express IRL
7.5. Pwnie express IRL
 
7.4. Show impact [bug bounties]
7.4. Show impact [bug bounties]7.4. Show impact [bug bounties]
7.4. Show impact [bug bounties]
 
7.3. iCloud keychain-2
7.3. iCloud keychain-27.3. iCloud keychain-2
7.3. iCloud keychain-2
 
7.2. Alternative sharepoint hacking
7.2. Alternative sharepoint hacking7.2. Alternative sharepoint hacking
7.2. Alternative sharepoint hacking
 
7.1. SDLC try me to implenment
7.1. SDLC try me to implenment7.1. SDLC try me to implenment
7.1. SDLC try me to implenment
 
6.3. How to get out of an inprivacy jail
6.3. How to get out of an inprivacy jail6.3. How to get out of an inprivacy jail
6.3. How to get out of an inprivacy jail
 
6.2. Hacking most popular websites
6.2. Hacking most popular websites6.2. Hacking most popular websites
6.2. Hacking most popular websites
 
6.1. iCloud keychain and iOS 7 data protection
6.1. iCloud keychain and iOS 7 data protection6.1. iCloud keychain and iOS 7 data protection
6.1. iCloud keychain and iOS 7 data protection
 
6. [Bonus] DCM MI6
6. [Bonus] DCM MI66. [Bonus] DCM MI6
6. [Bonus] DCM MI6
 
5.3. Undercover communications
5.3. Undercover communications5.3. Undercover communications
5.3. Undercover communications
 
5.2. Digital forensics
5.2. Digital forensics5.2. Digital forensics
5.2. Digital forensics
 
5.1. Flashback [hacking AD]
5.1. Flashback [hacking AD]5.1. Flashback [hacking AD]
5.1. Flashback [hacking AD]
 
5. [Daily hack] Truecrypt
5. [Daily hack] Truecrypt5. [Daily hack] Truecrypt
5. [Daily hack] Truecrypt
 
4.5. Contests [extras]
4.5. Contests [extras]4.5. Contests [extras]
4.5. Contests [extras]
 
4.4. Hashcracking server on generic hardware
4.4. Hashcracking server on generic hardware4.4. Hashcracking server on generic hardware
4.4. Hashcracking server on generic hardware
 
4.3. Rat races conditions
4.3. Rat races conditions4.3. Rat races conditions
4.3. Rat races conditions
 
4.2. Web analyst fiddler
4.2. Web analyst fiddler4.2. Web analyst fiddler
4.2. Web analyst fiddler
 
4.1. Path traversal post_exploitation
4.1. Path traversal post_exploitation4.1. Path traversal post_exploitation
4.1. Path traversal post_exploitation
 
3.3. Database honeypot
3.3. Database honeypot3.3. Database honeypot
3.3. Database honeypot
 
3.2. White hat
3.2. White hat3.2. White hat
3.2. White hat
 

Recently uploaded

Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Sheetaleventcompany
 
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...SofiyaSharma5
 
How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)Damian Radcliffe
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts servicevipmodelshub1
 
VIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
VIP Kolkata Call Girls Salt Lake 8250192130 Available With RoomVIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
VIP Kolkata Call Girls Salt Lake 8250192130 Available With Roomgirls4nights
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Roomdivyansh0kumar0
 
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts servicesonalikaur4
 
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$kojalkojal131
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersDamian Radcliffe
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGAPNIC
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.soniya singh
 
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkataanamikaraghav4
 
Radiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsRadiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsstephieert
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024APNIC
 

Recently uploaded (20)

Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
Call Girls Service Chandigarh Lucky ❤️ 7710465962 Independent Call Girls In C...
 
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Saket Delhi 💯Call Us 🔝8264348440🔝
 
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
Low Rate Young Call Girls in Sector 63 Mamura Noida ✔️☆9289244007✔️☆ Female E...
 
How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)How is AI changing journalism? (v. April 2024)
How is AI changing journalism? (v. April 2024)
 
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 22 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Alwarpet Phone 🍆 8250192130 👅 celebrity escorts service
 
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 6 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
VIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
VIP Kolkata Call Girls Salt Lake 8250192130 Available With RoomVIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
VIP Kolkata Call Girls Salt Lake 8250192130 Available With Room
 
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 26 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
Call Girls In Ashram Chowk Delhi 💯Call Us 🔝8264348440🔝
 
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130  Available With RoomVIP Kolkata Call Girl Kestopur 👉 8250192130  Available With Room
VIP Kolkata Call Girl Kestopur 👉 8250192130 Available With Room
 
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts serviceChennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
Chennai Call Girls Porur Phone 🍆 8250192130 👅 celebrity escorts service
 
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
Call Girls Dubai Prolapsed O525547819 Call Girls In Dubai Princes$
 
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 
Networking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOGNetworking in the Penumbra presented by Geoff Huston at NZNOG
Networking in the Penumbra presented by Geoff Huston at NZNOG
 
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Shahpur Jat Escort Service Delhi N.C.R.
 
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls KolkataRussian Call Girls in Kolkata Ishita 🤌  8250192130 🚀 Vip Call Girls Kolkata
Russian Call Girls in Kolkata Ishita 🤌 8250192130 🚀 Vip Call Girls Kolkata
 
Radiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girlsRadiant Call girls in Dubai O56338O268 Dubai Call girls
Radiant Call girls in Dubai O56338O268 Dubai Call girls
 
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
DDoS In Oceania and the Pacific, presented by Dave Phelan at NZNOG 2024
 

PHDays CTF 2014 Final Write-Up

  • 1. PHDays CTF 2014 Final Max Moroz June 07, 2014
  • 2. whoami Max Moroz  Captain  Job: C++, Objective-C, Java  Freelance: pentesting  Interests: crypto, forensic, misc BalalaikaCr3w
  • 9. • Ubuntu 14.04 • services: – cardbook (:1234) = 12 × 3 – mobol (:3123) = 24 × 2 – holynet (:80) = 48 × 1 #PREPARE TO BATTLE
  • 11. • tcpdump –A port 80 | grep ‘w{32}’ | nc $VODKA • tcpdump –A port 1234 | grep ‘w{32}’| nc $VODKA • tcpdump –A port 3123 | grep ‘w{32}’ | nc $VODKA #P0WN3R ACHIEVEMENT UNLOCKED
  • 12. DEBUG:root:new game! DEBUG:root:suits in game: ['S', 'D', 'C', 'H', 'E', 'A', 'T', 'Z'] DEBUG:root:received cards: set(['2ofE', 'AofD', '6ofA', 'KofH', '3ofA', '10ofT', '5ofH', '4ofH', '9ofH', '6ofS', 'AofT', 'AofZ', 'JofC', 'QofH', '3ofT', '4ofD', '8ofC']) DEBUG:root:state is 0, hand is 2ofE AofD 6ofA KofH 3ofA 10ofT 5ofH 4ofH 9ofH 6ofS AofT AofZ JofC QofH 3ofT 4ofD 8ofC DEBUG:root:Received: INFO: players in this session: [0, 2, 4, 5, 6, 7] <…> DEBUG:root:Received: TRICK SUCCEEDED DEBUG:root:state is 0, hand is DEBUG:root:Received: INFO: new round DEBUG:root:state is 0, hand is DEBUG:root:Received: END. WIN! Take your prizes: b1bbee3e61d9dbd2b808b9d6efc55ac6 2f00f06026cdabe99c09725431b84064 4ba4c7f5f44563c73be0a436f0474a4f ae2c9ce87ddafa1d8eb715eee6e61f4f c62c93363e933111a4dd502477b8d386 3dbf50201f9bc2e5b4d7d2f268b2e868 1f958958cead352be5810b49ca5ca378 8ba6516044e9926822a6dc85bdee591f e762d36f93384a29140f70c73d45e398 655cfa6d598710475734e50212d6ef5a DEBUG:root:game ended, I won ./cardbook • tail –f cardbook-stderr.log | grep ‘w{32}’ | nc $VODKA
  • 17. VODKA FLAGS STATISTICS: Flags found: 4426 Successfully sent: 1249 Waiting for resend: 85 Bad flags: 0 All Flags Submitted ./vodka --stat
  • 18. cat game_economics.txt Task Name Reward (gold) Price (Power) Price (Armor) Price (Fuel) crackme 1000 15 0 0 breadcrumbs 2500 12 16 1 musicforsoul 2500 15 4 6 mars2 2000 22 6 0 holygrail 2000 13 2 5 homepage 2500 4 8 8 doubleshizo 3000 0 21 5 oracle2 5000 19 27 6 mooditter 5000 64 5 2 pyhtonisback 1000 14 1 0 tera 2000 4 9 7 packIt9000 5000 4 7 21 Wolfram|ɛπτα 2000 18 5 2 lockpicking 2000 15 5 3 my favorite sequel 4000 8 22 7 schoolmath 2000 1 14 3 Total 43500 228 152 76 Gold from selling 3648 3648 3648
  • 19. cat game_economics.txt Task Name Reward (gold) Price (Power) Price (Armor) Price (Fuel) crackme 1000 15 0 0 breadcrumbs 2500 12 16 1 musicforsoul 2500 15 4 6 mars2 2000 22 6 0 holygrail 2000 13 2 5 homepage 2500 4 8 8 doubleshizo 3000 0 21 5 oracle2 5000 19 27 6 mooditter 5000 64 5 2 pyhtonisback 1000 14 1 0 tera 2000 4 9 7 packIt9000 5000 4 7 21 Wolfram|ɛπτα 2000 18 5 2 lockpicking 2000 15 5 3 my favorite sequel 4000 8 22 7 schoolmath 2000 1 14 3 Total 43500 228 152 76 Gold from selling 3648 3648 3648
  • 21. cat game_economics.txt Task Name Reward (gold) Price (Power) Price (Armor) Price (Fuel) crackme 1000 15 0 0 breadcrumbs 2500 12 16 1 musicforsoul 2500 15 4 6 mars2 2000 22 6 0 holygrail 2000 13 2 5 homepage 2500 4 8 8 doubleshizo 3000 0 21 5 oracle2 5000 19 27 6 mooditter 5000 64 5 2 pyhtonisback 1000 14 1 0 tera 2000 4 9 7 packIt9000 5000 4 7 21 Wolfram|ɛπτα 2000 18 5 2 lockpicking 2000 15 5 3 my favorite sequel 4000 8 22 7 schoolmath 2000 1 14 3 Total 43500 228 152 76 Gold from selling 3648 3648 3648