nalo.dev
Writeups
Toggle theme
Day 19
Huntress CTF 2024
1 min read
(33 min read total)
Day 1
3 min read
Day 2
1 min read
Day 3
5 min read
Day 4
1 min read
Day 5
1 min read
Day 6
2 min read
Day 7
1 min read
Day 8
5 min read
Day 9
3 min read
Day 10
1 min read
Day 11
1 min read
Day 12
1 min read
Day 13
2 min read
Day 14
1 min read
Day 15
2 min read
Day 16
2 min read
Day 17
4 min read
Day 18
1 min read
Day 19
1 min read
Day 20
1 min read
Day 21
1 min read
Overview
malware/eco-friendly
rev/stack-it
Writeups
Huntress CTF 2024
Day 19
Day 19
n
nalo_
October 19, 2024
1 min read
ctf
writeup
huntress
Previous Subpost
Day 18
Parent Post
Huntress CTF 2024
Next Subpost
Day 20
Table of Contents
Subposts
Day 1
warmup/technical-support
warmup/too-many-bits
warmup/matryoshkaqr
warmup/read-the-rules
scripting/base64by32
malware/strange-calc
Day 2
misc/red-phish-blue-phish
crypto/no-need-for-brutus
Day 3
warmup/cattle
forensic/nightmare-on-hunt-street
Challenge 1: What is the IP address of the host that the attacker used?
Challenge 2: How many times was the compromised account brute-forced?
Challenge 3: What is the name of the offensive security tool that was used to gain initial access?
Challenge 4: How many unique enumeration commands were run with net.exe?
Challenge 5: What password was successfully given to the user created?
malware/russian-roulette
Day 4
warmup/whamazon
misc/malibu
Day 5
warmup/unbelievable
Ocean Lust
Day 6
warmup/txt-message
warmup/discount-programming-devices
Day 7
malware/mimi
misc/system-code
Day 8
forensic/zimmer-down
osint/ran-somewhere
misc/base-p
warmup/mystery
Day 9
misc/i-cant-ssh
rev/gocrackme1
Day 10
warmup/finders-fee
rev/gocrackme2
Day 11
warmup/typo
rev/gocrackme3
Day 12
warmup/zulu
malware/x-ray
Day 13
forensic/obfuscation-station
forensic/little-shop-of-hashes
Challenge 1: What is the name of the service that the attacker ran and stopped, which dumped hashes on the first compromised host?
Challenge 2: What lateral movement technique did the threat actor use to move to the other machine?
Challenge 3: What is the full path of the binary that the threat actor used to access the privileges of a different user with explicit credentials?
Challenge 4: How many accounts were compromised by the threat actor?
Challenge 5: What is the full path of the binary that was used as a callback to the threat actor’s machine?
Day 14
forensic/hidden-streams
forensic/keyboard-junkie
Day 15
misc/sekiro
misc/1200-transmissions
Day 16
scripting/echo-chamber
Method 1: Extract flag from data
Method 2: Build back the transfered image
Day 17
warmup/the-void
misc/linux-basics
Question 0: What’s your home directory?
Question 1: Search the man pages. What command would you use to generate random permutations?
Question 2: On what day was /home/user/myfile.txt modified? Use the date format 2019-12-31
Question 3: How big is /home/user/myfile.txt, in kilobytes? Round to the nearest whole number.
Question 4: What user owns the file /home/user/myfile.txt
Question 5: What’s the 3-digit octal permissions of the file /home/user/myfile.txt? (e.g 777)
Question 6: What is the user id of ‘admin’?
Question 7: There is a user ‘john’ on the system. Can they write to /home/user/myfile.txt? (yes/no)
Question 8: Can the ‘admin’ user execute /home/user/myfile.txt? (yes/no)
Question 9: Which user on the system, except for you, root, admin and john, can execute /home/user/myfile.txt?
Question 10: /home/user/myfile.txt looks like a txt file, but it actually isn’t. What kind of file is it?
pwn/baby-buffer-overflow-32bit
web/moveable
Day 18
malware/eepy
misc/permission-to-proxy
Day 19
malware/eco-friendly
rev/stack-it
Day 20
web/y2j
forensic/backdoored-splunk-ii
Day 21
crypto/strive-marish-leadman-typecdr
web/helpful-desk
malware/eco-friendly
Eco-Friendly
Category
malware
TODO
rev/stack-it
Stack It
Category
rev
TODO
Huntress CTF 2024
1 min read
(33 min read total)
Day 1
3 min read
Day 2
1 min read
Day 3
5 min read
Day 4
1 min read
Day 5
1 min read
Day 6
2 min read
Day 7
1 min read
Day 8
5 min read
Day 9
3 min read
Day 10
1 min read
Day 11
1 min read
Day 12
1 min read
Day 13
2 min read
Day 14
1 min read
Day 15
2 min read
Day 16
2 min read
Day 17
4 min read
Day 18
1 min read
Day 19
1 min read
Day 20
1 min read
Day 21
1 min read
Previous Subpost
Day 18
Parent Post
Huntress CTF 2024
Next Subpost
Day 20