{"id":76,"date":"2017-10-19T16:13:26","date_gmt":"2017-10-19T16:13:26","guid":{"rendered":"http:\/\/hackerintent.co.nf\/?p=76"},"modified":"2017-10-19T16:13:26","modified_gmt":"2017-10-19T16:13:26","slug":"2014-cysca-om-nom-nom","status":"publish","type":"post","link":"https:\/\/takeondevops.com\/?p=76","title":{"rendered":"2014 CySCA Om Nom Nom"},"content":{"rendered":"<p>This penetration test assignment is done for the OM NOM NOM NOM Challenge of CYSCA2014. When we hear the term OM NOM NOM NOM what comes to our mind, is that that is the sound made by the cookie monster on the \u201cSesame Street\u201d TV show. So this could be something to do with cookies.<\/p>\n<p>To get started with the CYSCA 2014 we need to set up the static IP address configurations in the CYSCA2014 Box and restart it.<\/p>\n<p>I have changed my IP in the Linux Box to 192.168.1.5. Also I have started Burpsuite and configured the browser to allow Burpsuite to intercept the requests and responses sent to our target website.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i2.wp.com\/farm5.staticflickr.com\/4494\/37744422056_fac6e16e55_b.jpg?w=756&#038;ssl=1\" alt=\"dashboard\" data-recalc-dims=\"1\" \/><br \/>\nNext, we can click on the link available on the homepage that directs us to the fortress page. Notice that in this page the link to the Blog in the main menu is disabled to us. This means that we need higher privileges to access this.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.wp.com\/farm5.staticflickr.com\/4491\/37535091660_9c77dbbcc1_z.jpg?w=756&#038;ssl=1\" alt=\"blog\" data-recalc-dims=\"1\" \/><br \/>\nIn order to access the blog, we will need to intercept the requests sent from the initial website to the fortress website. This could be done by changing the vip query parameter from 0 to 1. An easier way to do this by setting the cookie by navigating to Project Options -&gt; Sessions -&gt; Cookie jar and editing the value corresponding to the \u2018vip\u2019 attribute in Burpsuite. This did not work for me hence I had to do it manually by changing every request\u2019s vip value from 0 to 1.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i2.wp.com\/farm5.staticflickr.com\/4444\/23940554358_645aae52c0_z.jpg?w=756&#038;ssl=1\" alt=\"\" data-recalc-dims=\"1\" \/><br \/>\nThe above screenshot shows how the cookie can be edited.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.wp.com\/farm5.staticflickr.com\/4445\/37745631736_92a6a3a681_b.jpg?w=756&#038;ssl=1\" alt=\"\" data-recalc-dims=\"1\" \/><br \/>\nAbove screenshot shows how the cookie attribute \u2018vip\u2019 was changed to 1. By doing so we can access the blog. Under the blog section, we click on the \u2018New feature\u2019 link.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i2.wp.com\/farm5.staticflickr.com\/4486\/37792984601_be03aa9b7f_b.jpg?w=756&#038;ssl=1\" data-recalc-dims=\"1\" \/><br \/>\nThe new features section allows us to post comments. (By the way, we need to make sure we intercept and change the value of the vip attribute every time a link and every time, it shows up in burpsuite to forward or drop a request. Otherwise we would be automatically signed off.) This comments section allows us to type anything we want. Let us see if there are any XSS vulnerability that we can exploit.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i1.wp.com\/farm5.staticflickr.com\/4473\/37746443506_614dd4b5ac_b.jpg?w=756&#038;ssl=1\" data-recalc-dims=\"1\" \/><br \/>\nAfter the script was typed in and the add comment was clicked, this showed up. Now we know there is a XSS vulnerability. Let us execute some code to steal the cookie<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.wp.com\/farm5.staticflickr.com\/4485\/37792960991_67c1b27219_b.jpg?w=756&#038;ssl=1\" data-recalc-dims=\"1\" \/><br \/>\nThis is the script written to steal the cookie.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i2.wp.com\/farm5.staticflickr.com\/4465\/37763308792_a4e66ab816_b.jpg?w=756&#038;ssl=1\" data-recalc-dims=\"1\" \/><br \/>\nNext, we set up the webserver and post a comment that uses the script in our server to steal the cookie.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i1.wp.com\/farm5.staticflickr.com\/4460\/37744380046_f20a86de62_b.jpg?w=756&#038;ssl=1\" data-recalc-dims=\"1\" \/><br \/>\nOnce we do this we can see the cookies in our terminal window. The first one is the cookie of the current user. So that is no use.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i0.wp.com\/farm5.staticflickr.com\/4447\/37085725794_1c72ecf427_b.jpg?w=756&#038;ssl=1\" data-recalc-dims=\"1\" \/><br \/>\nSo, let us copy another cookie into the current cookie in our Burpsuite cookie jar.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i2.wp.com\/farm5.staticflickr.com\/4483\/37744372266_5947544b88_b.jpg?w=756&#038;ssl=1\" data-recalc-dims=\"1\" \/><br \/>\nNow when we refresh the page, we can see the flag. So now we have captured the flag<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i2.wp.com\/farm5.staticflickr.com\/4480\/37744360026_b8dd718088_b.jpg?w=756&#038;ssl=1\" data-recalc-dims=\"1\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This penetration test assignment is done for the OM NOM NOM NOM Challenge of CYSCA2014. When we hear the term OM NOM NOM NOM what comes to our mind, is that that is the sound made by the cookie monster on the \u201cSesame Street\u201d TV show. So this could be something to do with cookies. [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","footnotes":""},"categories":[2,3,5,6],"tags":[],"class_list":["post-76","post","type-post","status-publish","format-standard","hentry","category-ctf","category-dev","category-infosec","category-network"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>2014 CySCA Om Nom Nom - Take On Devops<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/takeondevops.com\/?p=76\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"2014 CySCA Om Nom Nom - Take On Devops\" \/>\n<meta property=\"og:description\" content=\"This penetration test assignment is done for the OM NOM NOM NOM Challenge of CYSCA2014. When we hear the term OM NOM NOM NOM what comes to our mind, is that that is the sound made by the cookie monster on the \u201cSesame Street\u201d TV show. So this could be something to do with cookies. [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/takeondevops.com\/?p=76\" \/>\n<meta property=\"og:site_name\" content=\"Take On Devops\" \/>\n<meta property=\"article:published_time\" content=\"2017-10-19T16:13:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/farm5.staticflickr.com\/4494\/37744422056_fac6e16e55_b.jpg\" \/>\n<meta name=\"author\" content=\"ihsan izwer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ihsan izwer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76\"},\"author\":{\"name\":\"ihsan izwer\",\"@id\":\"https:\\\/\\\/takeondevops.com\\\/#\\\/schema\\\/person\\\/465f2fb632235eb4079002754cd66aeb\"},\"headline\":\"2014 CySCA Om Nom Nom\",\"datePublished\":\"2017-10-19T16:13:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76\"},\"wordCount\":488,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/farm5.staticflickr.com\\\/4494\\\/37744422056_fac6e16e55_b.jpg\",\"articleSection\":[\"CTF\",\"Dev\",\"InfoSec\",\"Network\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/takeondevops.com\\\/?p=76#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76\",\"url\":\"https:\\\/\\\/takeondevops.com\\\/?p=76\",\"name\":\"2014 CySCA Om Nom Nom - Take On Devops\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/takeondevops.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/farm5.staticflickr.com\\\/4494\\\/37744422056_fac6e16e55_b.jpg\",\"datePublished\":\"2017-10-19T16:13:26+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/takeondevops.com\\\/#\\\/schema\\\/person\\\/465f2fb632235eb4079002754cd66aeb\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/takeondevops.com\\\/?p=76\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76#primaryimage\",\"url\":\"https:\\\/\\\/farm5.staticflickr.com\\\/4494\\\/37744422056_fac6e16e55_b.jpg\",\"contentUrl\":\"https:\\\/\\\/farm5.staticflickr.com\\\/4494\\\/37744422056_fac6e16e55_b.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/takeondevops.com\\\/?p=76#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/takeondevops.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"2014 CySCA Om Nom Nom\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/takeondevops.com\\\/#website\",\"url\":\"https:\\\/\\\/takeondevops.com\\\/\",\"name\":\"Take On Devops\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/takeondevops.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/takeondevops.com\\\/#\\\/schema\\\/person\\\/465f2fb632235eb4079002754cd66aeb\",\"name\":\"ihsan izwer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c82c3d13c92d77259746074978cb7d498778b44914dea60ad0367dec237c349f?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c82c3d13c92d77259746074978cb7d498778b44914dea60ad0367dec237c349f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/c82c3d13c92d77259746074978cb7d498778b44914dea60ad0367dec237c349f?s=96&d=mm&r=g\",\"caption\":\"ihsan izwer\"},\"url\":\"https:\\\/\\\/takeondevops.com\\\/?author=3\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"2014 CySCA Om Nom Nom - Take On Devops","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/takeondevops.com\/?p=76","og_locale":"en_US","og_type":"article","og_title":"2014 CySCA Om Nom Nom - Take On Devops","og_description":"This penetration test assignment is done for the OM NOM NOM NOM Challenge of CYSCA2014. When we hear the term OM NOM NOM NOM what comes to our mind, is that that is the sound made by the cookie monster on the \u201cSesame Street\u201d TV show. So this could be something to do with cookies. [&hellip;]","og_url":"https:\/\/takeondevops.com\/?p=76","og_site_name":"Take On Devops","article_published_time":"2017-10-19T16:13:26+00:00","og_image":[{"url":"https:\/\/farm5.staticflickr.com\/4494\/37744422056_fac6e16e55_b.jpg","type":"","width":"","height":""}],"author":"ihsan izwer","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ihsan izwer","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/takeondevops.com\/?p=76#article","isPartOf":{"@id":"https:\/\/takeondevops.com\/?p=76"},"author":{"name":"ihsan izwer","@id":"https:\/\/takeondevops.com\/#\/schema\/person\/465f2fb632235eb4079002754cd66aeb"},"headline":"2014 CySCA Om Nom Nom","datePublished":"2017-10-19T16:13:26+00:00","mainEntityOfPage":{"@id":"https:\/\/takeondevops.com\/?p=76"},"wordCount":488,"commentCount":0,"image":{"@id":"https:\/\/takeondevops.com\/?p=76#primaryimage"},"thumbnailUrl":"https:\/\/farm5.staticflickr.com\/4494\/37744422056_fac6e16e55_b.jpg","articleSection":["CTF","Dev","InfoSec","Network"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/takeondevops.com\/?p=76#respond"]}]},{"@type":"WebPage","@id":"https:\/\/takeondevops.com\/?p=76","url":"https:\/\/takeondevops.com\/?p=76","name":"2014 CySCA Om Nom Nom - Take On Devops","isPartOf":{"@id":"https:\/\/takeondevops.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/takeondevops.com\/?p=76#primaryimage"},"image":{"@id":"https:\/\/takeondevops.com\/?p=76#primaryimage"},"thumbnailUrl":"https:\/\/farm5.staticflickr.com\/4494\/37744422056_fac6e16e55_b.jpg","datePublished":"2017-10-19T16:13:26+00:00","author":{"@id":"https:\/\/takeondevops.com\/#\/schema\/person\/465f2fb632235eb4079002754cd66aeb"},"breadcrumb":{"@id":"https:\/\/takeondevops.com\/?p=76#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/takeondevops.com\/?p=76"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/takeondevops.com\/?p=76#primaryimage","url":"https:\/\/farm5.staticflickr.com\/4494\/37744422056_fac6e16e55_b.jpg","contentUrl":"https:\/\/farm5.staticflickr.com\/4494\/37744422056_fac6e16e55_b.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/takeondevops.com\/?p=76#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/takeondevops.com\/"},{"@type":"ListItem","position":2,"name":"2014 CySCA Om Nom Nom"}]},{"@type":"WebSite","@id":"https:\/\/takeondevops.com\/#website","url":"https:\/\/takeondevops.com\/","name":"Take On Devops","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/takeondevops.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/takeondevops.com\/#\/schema\/person\/465f2fb632235eb4079002754cd66aeb","name":"ihsan izwer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/c82c3d13c92d77259746074978cb7d498778b44914dea60ad0367dec237c349f?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/c82c3d13c92d77259746074978cb7d498778b44914dea60ad0367dec237c349f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/c82c3d13c92d77259746074978cb7d498778b44914dea60ad0367dec237c349f?s=96&d=mm&r=g","caption":"ihsan izwer"},"url":"https:\/\/takeondevops.com\/?author=3"}]}},"jetpack_featured_media_url":"","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/takeondevops.com\/index.php?rest_route=\/wp\/v2\/posts\/76","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/takeondevops.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/takeondevops.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/takeondevops.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/takeondevops.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=76"}],"version-history":[{"count":0,"href":"https:\/\/takeondevops.com\/index.php?rest_route=\/wp\/v2\/posts\/76\/revisions"}],"wp:attachment":[{"href":"https:\/\/takeondevops.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=76"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/takeondevops.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=76"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/takeondevops.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=76"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}