Linux privilege escalation involves gaining elevated system access through three primary methods: (1) Path hijacking exploits the PATH environment variable by adding writable directories to execute malicious binaries when privileged programs run commands without absolute paths; (2) Capabilities allow binaries to operate with specific privileges beyond standard file permissions, and can be exploited when normal user-accessible binaries have dangerous capabilities like cap_setuid; (3) Cron jobs can be modified to execute malicious commands as root since they run with elevated privileges. These techniques demonstrate how attackers leverage system configuration weaknesses to escalate from user to root access.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
PRIVILEGE ESCALATION LIVE! TryHackMe Kenobi & Linux Hacking
Added:Hey, hey, hey.
Hey, hey, hey.
Heat.
Heat.
Hey, hey, Hey, hey, hey.
Hey, hey, hey.
Heat. Heat.
Hide the planet. Hide the planet.
We're in.
>> Shall we play a game?
>> How about global thermonuclear war?
Hey there hacker frogs. It's me, the shy hat, and we're doing Hacker Frogs free hacking today. We're doing Hacker Frogs after school. We're hacking all the things. So, let me let me change up my overlays. Just a second. So today we're doing network hacking session 10 and we're also doing labs Gotham. So I need to put that on my overlay. Docker Labs Gotham.
Okay. And uh let's talk about what we're going to be doing on today's schedule.
So um this is web app Wednesday. Well, supposed to be web app Wednesday. And we don't necessarily do web apps, but uh the alliteration's nice. So we're doing four different topics today. The first topic we're going to be doing is we're going to be playing a little puzzle game called Desktop Explorer. It's also got some horror elements, so we'll see how that goes. That's going to be the first hour of today's stream. In the second hour, I'm g I'm going to be doing a network hacking demonstration of the tryhackme room Kenobi. It's a relatively easy network hacking room, and we're going to be uh exploring how to finish this. I'll try to explain as best as possible how to do the network hacking on this particular box. So, that's the second hour. For the third hour, we're going to be doing Hacker Frogs After School. This is the last session of network hacking, and we're going to be talking about Linux privilege escalation techniques. This is the second part of the series and we're going to be talking about how to get root and um because everybody's all about that. So that's the third topic. In the fourth topic which is going to go for maybe two or three hours, we're going to be doing Docker Labs Gotham. So this is a vulnerable Docker machine that we deploy on our own and our on our own system and then we hack against it until we get super user access. So that's what we're going for.
Okay. Cisco says, "Is it going to contain Microsoft products?" Uh, maybe. It's probably going to be very reminiscent of old Windows.
But, uh, the game, you can find it over here.
I guess you could say that's the the horror element of the game. So, without further ado, well, we've got the scary evil clippy over here. Evil notepad, I guess. Anyways, let's go ahead and give ourselves about uh just for fun, we'll give ourselves 65 minutes to work on this and let's get started. So, I'll start up the game.
And if you want to talk about cyber security stuff, if you want to talk about tech stuff, if you just want to keep on chatting while the game is going on, that's completely fine.
I'm talking about horror elements.
That's where my mind went. Okay. Okay.
Okay. And you should be able to hear the game as well.
Desktop Explorer inter interface mystery adventure.
Okay. So, we'll start it. This is the demo version of the game and we're going to go ahead and give it a try. If we really like it, we might get the full version and try that out. So, we will do a new game.
So, this is relevant of old PCs.
All right. So, it looks like we've got Next OS. Next OS. I wonder if this is supposed to be similar to Windows more or similar to Linux more or something else. So, we've got uh three users to try to log in as the admin user, the Maximus user, and the Halibet user.
So, the Maximus user and the admin user both have passwords, but but the Halibit user doesn't. So, I guess we can log in.
Red Sly Fox says, "An normal time today, IBM OS2." OS2. That's a That's a call back. Or a call back to the next computer system. Next computer system.
All right. So, task list. Replace mouse and keyboard. Buy speakers compatible with PC. Connect to the internet. Edit.
Ethernet port is completely broken. Uh, check software. It should be in my start menu at the bottom left of my desktop.
So, you can't see the the bottom of the screen. I'm not I'm not too sure why I'm not able to capture that, but there's a there's a little like Windows like start button over here in the corner H.
We can also change up the volume mixer.
I think the the game sounds might be a little bit too low. I'll I'll turn them up a little bit. If they're too loud, let me know.
Okay. So, what we need to do is check the Chronologue software. It should be on the bottom left of my desktop. Bottom left.
Chronolog.
Here it is. Okay. Chronologue.
Okay. Welcome to Chronologue. Select an entry to read its contents or create a new one to get started. Happy journaling.
Okay. For the brightest last in the seven seas, every day it becomes a bit harder for me to remember. Every once in a while, I'll have what my doctor calls lucid periods and recall memories I may never think of again. I leave you this information along with my computer.
There are other users, the previous owners of this computer. There's a strange program called desktop explorer.
It's inside the open me folder on my desktop. The password for you is your nickname. Your nickname. Uh, I guess we're the Halibet user, so I guess the nickname is Halibet. Three. It's all related to the disappearance of someone I cared about.
Okay, let's uh let's be nice and chat.
Thank you very much. Thank you very much. Okay, so in this computer you'll find my most intimate thoughts. I trust you with them since you the only thing I admire more than your wits is your kind heart. I want to end this letter with a poem.
If we're apart, look at the moon, for I will do, too. If we're apart, look at the moon, for I will do, too. If I am gone, look at the stars, for I am with you. Goodbye, Guppy, your uncle. So, Guppy is our uncle.
So, we got H. We have Halibet's journal, and we got Guppy's journal.
Can we write something? Guppy's detective log. Today was the last day before my uncle left for intensive care. It was very surreal having him hug me while I was crying because he didn't even know why I was so sad in the first place. This is his old computer. So, we're Guppy. Are we Guppy or are we Halipit? I can't I can't tell.
Yeah. Okay. Let's uh let's keep it civil in the chat. Thank you.
Uh, this is his old computer. So, this is my uncle's computer.
I replaced the mouse, keyboard, and speakers, but I couldn't hook it up to any internet connection. It doesn't really matter. Everything I need is here. I just read the letter he left me.
I thought I had no more tears left in me, but I was wrong. I feel like this is the start of a detective mission.
It's time to install Desktop Explorer and see what this is about. The password for the folder, Uncle Hell, was the only one to call me by that nickname. This one's for you, Captain Halibet. Okay, we need to open up desktop explorer. I'm guessing it's this one. This one over here.
This file's password. Hell incorrect password. Um, Guppy.
Okay, so this is desktop explorer installer.exe.
So, I mean, these files are called.exe files. So, it kind of it kind of um makes me think that we're dealing with something that's more similar to Windows and we'll meet the evil notepad clippy type guy. Here we go. Wait a second.
Wait a second. I remember you. Do you remember me? It's your old friend Pizaro.
Uh, I don't blame you. After all, it's been a while, hasn't it?
I'll go over everything as it were your first time installing Desktop Explorer.
Desktop Explorer offers the best experience when understanding the user's needs. Let's see what we're working with. Is this a clippy reference?
Probably. Probably.
Wow, I see you're a pretty average user.
Nothing wrong with that. That's great.
You'll be presented with puzzles around basic computer usage. Pretty simple stuff.
Puzzles will look like this. So, example puzzle, next puzzle, notes.npg.
Okay. Your goal is to find the password and unlock the next puzzle folder.
Okay. It won't always be this easy, though. Also, sub menus are your friends.
Most programs have sub menus. These tools could come in handy, you know. So, to sort by name, size, type, date, hidden files. H. Okay.
Who knows what you might find.
These puzzles will test your ability to think outside the box.
The world's your oyster.
Be creative and have fun. Try to try to keep up and remember all the details.
Okay, take your time, my friend. Good luck. Okay, so I guess we need to solve some puzzles.
Puzzle zero prologue.
You're proceeding without reading readme.npg.
Desktop Explorer encourages you to read it first. This message will not be displayed again.
Okay, so we need to read the NPG file first before we do anything else.
So, where's the MPG file?
So, puzzle zero prologue. So, your image image. So, your hand. And we got our cave mouth over here.
Let's organize our windows as best we can.
Lost on the shore.
You are lost. You find yourself between the sea and a lush forest. Dragging your feet in the sand of a beach you've never seen before. Aside from your wits and senses, you bear only a small compass which has been damaged in a fall. Among the shores dark rocks, you spot what looks like to be the entrance of a cave.
Approaching it reveals the entrance is narrower than you anticipated. Litters letters written in the sand start fading away as it starts to rain heavily.
Before taking shelter, you managed to read some of it. You assume it's the cave. The cave's name. Fortuna.
About as creepy as the paper clip. Yeah.
Yeah, I guess so. Can we make this bigger?
Like zoom in? Uh, we can. Okay, we can make the the text bigger, which is going to help for well for everybody really.
Nitro Base, hello. Nice to see you here.
We're currently playing a game called Desktop Explorer as our warm-up.
The cave's name is Fortuna. All right.
So, puzzle one. Go in. Go in.
Input the files password. So, we know we have a what could be a password.
Fortuna.
Good job. With that, we start our adventure.
Okay. Um, so inside the cave and a torch.
Let's close out these files here. So inside the cave, it looks like this.
Good luck. Thank you. And we've got our torch inside. STP STP and long scroll.
Okay, so what does it say here?
Chant my ch my name, O child, and your voice will bear my fire.
When dusk surrounds me, Jana lights my path. So Anana and Nana lights my path.
So that might be another password.
What about inside STP?
So, as you glance up inside your new shelter, you notice a few cracks between the boulders on top. You quickly realize, did you go to Defcon? Uh, Defcon is in August, isn't it? I've never been to Defcon before and I'm not going this year, but uh but it is kind of like a hacker hacker mecca, I guess.
You quickly realize the na lack of natural light in here despite not being able to see much in the cave's darkness.
You stumble upon a stick next to a rolledup scroll. As you open it, you discover it's comically long.
Okay. And they they mention something about source code. So, this is like a script file.
So this is the source code for the script file here.
So we might have to take advantage of the source code in a few of these puzzles.
Okay. So ancient ins I guess the what we need to do here is just give the password. So, Inana.
Okay. Nice. The torch from this. The light from this torch is as bright as you. Wow.
Okay. Advanced. Ye. Advanced hackers here. Well, we try. Two days of live streams in a row. You know how to make a week a whole lot funner. Thanks. Thanks, Persona Management. I uh I appreciate that you like the streams. Okay, so this is puzzle part three.
What is this res file? Wide papyrus strip.npeg.
Okay, you wouldn't call it a nose, but you wouldn't call it a nose. Why would you What would you call it? Nobody knows. But there lies the answer. Nobody knows. But there lies the answer. So the answer if you don't call it a nose.
It's not a nose. What is the answer?
Nobody knows.
So a resource file. Haven't seen those in ages. H res files. Okay. So let's take a look at the resource file.
Ah, okay.
So, I've noticed that I keep writing depressive thoughts. So, today I will write one of my favorite memories. I don't remember the exact date, but this was the birth of the short-lived Angller Trio. Little Guppy's first fishing trip, and she blessed us with a honey hole.
So, are we um are we a girl? Are we a woman?
She blessed us with a honey hole. We are guppy.
Okay, it's just custom naming. Ignore the extensions. I mean, I guess the the extensions are kind of based on like real computer systems, but who knows? We filled the boat so fast that old walleye started singing again. When we got home, we toasted with pap and baby formula.
Oh, how I miss you, big bro. My memory might falter sometimes, but I won't forget your name anytime soon since Guppy has your melancholic eyes.
It's funny how I can't think of us three without using our code names, but I wouldn't have it any other way. As long as our young last breathe, the angller trio lives on.
Okay. If you advanced, if you hit advanced level, you need to read paper search. Read paper search. I mean, we might have to do some research outside of the game. It might be one of those games.
Okay. So, Chronologue um updated automatically. I guess if it's not a nose, what would you call it? Nobody knows. But there lies the answer. What kind of riddle is this?
You wouldn't call it a nose, but what would you call it? Nobody knows. But there lies the answer.
Okay, let's make this um nice and big.
This is as big as you get it. After pronouncing the name you read, the tip of the stick you were holding kindled into a soft flame. You now hold a torch of suspicious origin. With the newly lit path, you press on to a room with a wide strip of papyrus on the floor.
You notice you notice strokes and writing scattered on it along with some suspicious looking creases. You read, "Answer quickly and answer proud. Oh, solve my riddle. Say it loud. I garden the flowers with my hose. Wouldn't you know it, I use my nose. The rest is lost within the paper's folded format. Folded format. What?
Sounds like a Doctor Who reference. Who knows? Who knows? H.
Okay, so we need to figure out what the what the puzzle answer is.
Nobody knows.
What would you call it?
Nobody knows.
Okay. Input the files password. Nobody.
Not the correct password.
Nobody knows. You don't call it a nose.
Not a nose. Not a nose.
Secret.
Nobody knows. The answer is secret.
Secret.
Nope.
The Timu Clippy doesn't have a nose.
Hello. What can I do for you? Uh, talk to me. Did you know Pizaro was the name of a famous explorer? Um. H. Unknown.
Unknown. Unknown.
Okay, let's I think we might be able to take a look at the Can we We can't resize the window.
There lies the answer. And we also see some um some markings over here.
Nobody knows. But there in lies the answer. Oh, you know what?
Maybe there's something hidden in here if we scroll cuz this is really long.
Okay. Cipher, hello. Nice to see you here.
So, we're looking for a word.
We're looking for a word or something hidden in the scroll here.
Oh, okay. Ignifer, hello. Nice to see you here. Okay. I mean, I saw some I did see some letters, so we can zoom in.
Let's just keep on scrolling until until we see letters. So, we see FE.
I'll just um I'll just write these down.
I see a I see X, we see RT. But then again, we also I think I also saw some um some like red brackets. So here's a red bracket. I see an E.
That's E L E L E. E L E P H A S S I mean my guess it would be something like elephant maybe change the format if that doesn't work of the text file change the format format word wrap Oh yeah. Okay. Okay.
Okay. Nobody knows. You wouldn't call it a nose. But would you what would we call it? Nobody knows. But there in lies the answer.
So I think yeah this is an elephant.
Oh this is clever. Okay. So eleph Okay. Don't you love riddles? Keep it up. Thank you very much for the suggestion on changing the format.
Greywolf Netty, thank you. It's a picture. Yeah. Yeah. Don't you love riddles? Keep it up. Okay, so we've solved a number of riddles.
So, puzzle 4, crossroads, detective memories.stp.
Let's close this out.
As you solve the riddle after folding the papyrus, the elephant's trunk points to a path in the distance. Was it always there? You make your way through the passageway, which leads to an empty enclosed space within the cavern. It seems to be a dead end.
Just as you start to lose hope and begin to head back, you recall the words of advice from a detective show you watched as a kid. Read between the lines and find the source of the truth. Only then will you crack the code. You think there are no lines on these cave walls, detective or not, what am I supposed to do? So we can view the source code of this file and let's go ahead and make everything as big as possible.
Okay, so we've got comments inside the source code. So this is this is more like CTFs than we might want to think.
So on the left you notice a wall that is thinner than the others. The word self is inscribed on it. So self is the password.
Okay. Oh, wow. Look at Mr. Hacker over here. You're thorough.
Okay. So, what do we have now?
We've got left door, right door, key.
Eerr. So, this is like a corrupted file or something. and three paths. STP.
Okay. Could not open file. Contents may be corrupted. So, we've got a corrupted key file. We've got uh left door and right door.
I guess we should read the the script file first.
Watching all those detective shows has definitely paid off. Passing both of your hands over this cave walls cave's walls revealed to be a different to be different from all the others. A light push is all needed to crumble.
Hidden behind this neat ruse, you encounter three doors. Two of them lie beside you and the largest one in front of you. Below the central door, there's a yellow key. You try you try your luck using it, but the door won't budge.
There's an engraving on the key, but it's very hard to read.
Very hard to read. So, is there anything we can do with the key here? So, rename duplicate properties. Delete. Reto.
Restore file to original state. Maybe we can copy it.
Okay. And then maybe we can take a look at its properties.
Unknown file type puzzle for crossroads key one. Okay, so H.
Let's take a look at the right door.
Right room.
Rune. So there's a rune over here. Rena.
Rena.
Okay.
So, as you open it, you see a wall with a rune inscript uh inscripted painted on it. Below the rune, you see the word and alphabet you can read. Is this related to the other door? So, Raina, let's go to the other door.
Rena.
Rena.
Rename it. Oh, rename it. So, we need to rename the the key, right?
So, let's delete this and we'll rename this file. So, key.
I don't know. um renamed key.
NexOS cannot can't convert the file to the extension specified. File contents may be unreadable. So we might need to change the file extension.
So we'll just give it like key.
Please use a valid file extension when you rename. So, NPG, STP, etc. Maybe we need to make this an NPG file.
Now, we can read it.
You hold the key tightly and concentrate. You're very close, but you struggle to form a clear image in your mind. So, we need to make this an image file.
So rename img.
Okay. And it says every lock obeys.
Portonus portus.
Porto.
Okay.
Okay. Are you not able to identify file type? Um, I guess the file types in this game are a bit different from Well, they're kind of similar to real world computers. What great imagination you have. Great work. Good.
Okay. And so big door. All right. What do we have here? Small rooms. We got etched wall.
What does it say? Dare to say my name.
Say my name. Say my name.
Small rooms.SSTP. Let's take a look at Let's take a look at the um at the journal entry.
My doctor suggested I write about this line by line, so I'll give it a go. My big brother died on a rainy day. The rain wasn't enough to smother the flames. I couldn't help at all.
So, the big brother died in a fire.
I trembled for hours during that day. My big brother couldn't escape in time. I saw his face and body engulfed in fire.
That thing did not look like my big brother.
This is stupid. I don't need to recount step by step how my brother looked like a ghoul in his last moments. How is that supposed to help me? How is that supposed to end my headaches? I just ruined my morning writing this and I forget everything like everyone says. How is it that I can't forget my brother's withered face? How is that for amnesia?
H The the wall is completely covered with the phrase, "Dare to say my name."
Okay. And let's take a look at the Let's make this nice and big.
You reshape the key and reveal its message. You turn the lock with it. A small chamber like a closet is behind the big central door. The rock walls of this compartment are completely covered with the na same etched phrase, "Gare to say my name." You know from experience that speaking aloud holds some type of power. Examining the room, you are sure the only way forward is to call their name, whatever it may be.
Who wrote those words anyway? So, who is the person who wrote this?
Okay, let's take a look at the source code.
Ah, okay. So, there is something in the source code. Let's zoom in.
They didn't write their name on the wall, but still you feel as if you could figure out who the author is behind these etchings. The author.
So, we don't have like a big number of names that we've uncovered in this game.
So, where was the So, there's Guppy. There's Halibet.
Maybe it's Halibet.
Halibet.
Nope. Is it? Well, it's not probably not Guppy.
Oh, there was one other person who was mentioned in um in the journal, right?
Guppy's fishing trip. Uh walleye.
Walleye.
Maybe the the name is walleye.
Make it capitalized.
No.
Walleye guppy angler trio.
So, this entry was talking about this person's brother burning alive.
Okay. So, um I'm taking suggestions. If you think you know who the um who the author was, my guess is that it's either either the uncle or the or the brother cuz in the source code it says they didn't write their name on the wall, but still you feel as if you could figure out who the author is behind the etchings. So, who wrote these words?
So, my journal was talking about getting um getting your uncle's computer.
Okay, let's figure this out. Is it Pizarro?
No. Uh there's walleye.
There's halibit or maybe hell h. Okay, let's let's go through the um the files one more time.
The wall is completely covered with the phrase dare to say my name.
What are the properties here? Author MMTT MMTT. So maybe Oh, okay. Okay. Okay. All right. So that was you really have to do some uh some file forensics here, huh? Great thinking. What kind of name is that though? No idea.
Okay, so fleet face. Fleeting face. So we have Ooh, that's a scary looking face.
And we got flat stone.
Here's a flat stone.
fleeting face.stp.
So, let's talk about this face.
So, for a brief moment, you sense something behind you. Between the crevices of the wall, you are barely able to see what happens to be a human figure. After focusing a bit, you make out a withered face and a set of melancholic eyes.
melancholic eyes. I mean, we're I think our brother was supposed to have Sorry, our father was supposed to have mel melancholic eyes. As you take the first step towards it, the stranger runs off, leaving the the sound of pebbles tumbling on the ground. Okay, we'll take a look at the source code for this just to be thorough.
Nothing in the source code.
And then we've got this stone overwhelming dark.stp. STP.
Zoom in. Zoom in. As you pass your hand through the wall, the thought of a name you can't pronounce zooms through your mind. You close your eyes and shake your head briefly. As you open them again, in front of you, the darkest in front of you, the darkest passage so far is revealed to you. You delve inside. The torch you carry barely lights your arm while everything else is completely lost in blackness.
Joseph Elliot West, hello. Nice to see you here. How are you doing? We're just playing a a little puzzle game as a warm-up for the stream.
Shortly after, you start to doubt yourself and think of heading back. Your vision becomes completely devoid of light as the last spark from the stick expires. Rather than panicking, calm surrounds you. Somehow, you feel even more capable of revealing what's hidden in the dark. hidden in the dark.
Uh maybe we're supposed to look for hidden files.
Okay. Yeah, we can look for hidden files. I guess there's probably some sort of uh hint in the source code as well.
Concentrate on your field of view.
There's a way to reveal what is not meant to be seen. Okay, that's nice. Um let's take a look at this heightened senses hidden file.
The improvement of your vision has reached its peak. The dark still hinders your sight, but you feel comfortable moving within it. You even start noticing details in walls beyond arms reach. You find a boulder next to you with an engraved warning.
Engraved warning.
Okay, let's take a look at the source code.
Engraved warning.
Ah, okay. Here's the engraved warning here. So, this is a hidden image file.
Keep out. Reaching this point must have required courage, but going past it is utter foolishness. Heed my words and turn back now before it's too late.
Cassandra. So, this is probably the password for the next puzzle or for this puzzle.
Cassandra.
Wow. Nothing gets past you. Fishermen must have great eyesight. I guess fisherman.
Okay, we'll close this out.
So, let's see. Stelagmite formation. So we Okay, looks like we've got some letters. So R U B I Rubic Rubicon. Rubicon. So that's the name of the famous Roman river where Julius Caesar crossed to take over the Senate or something.
You ignore Cassandra's warning and press on. So, Cassandra is another myth mythological figure. Cassandra is like um was like a Greek prophet, I think.
But nobody would remember, nobody would believe her prophecies, but her prophecies always came true only to find a contrasting scene, a calm and lighted room surrounded by stellagmites.
You can clearly see the way forward, but your intuition tells you that these stagmites are worthy of attention. Your short break soothes your anxiety. You continue on.
Okay, so puzzle eight.
H dead end.
So here's our flat stone.
Here's our stagmite formation.
So, that looks like a tree or something.
Let's see if there are any hidden files in here. No hidden files in here.
Okay. Continuing the trial, the trail past it stagnite scene, you reach an uneventful dead end. Based on your experience during this exploration, you are convinced that there's something more than meets the eye. You spend your following hour inspecting every crevice of the walls that surround you. Now you can be absolute certain there is no path forward.
Okay. While scratching your head, pondering on what to do next, you hear a large thunk far off behind in the cave. Far off behind in the cave.
Okay, let's see if we can take a look at the source code for this.
The stagmite formation must have a purpose. Okay. And it sounded like it might have come from the entrance. Oh, so we need to go back.
Go back in the uh dark sanctum. Lights out. Big door.
Crossroads.
Narrow tunnel.
What happened to this puzzle? I don't remember these files being here earlier.
What's going on?
Okay, so we've got no escape, stuck, long scroll. I mean, these are the ones from before.
No escape dot.
This looks suspiciously like a face. We also have some runes. So these um kind of squiggly lines.
Okay. And what's this one? Puzzle to I mean we've solved this one already. So stuck H.
Even after retracing your steps perfectly, you doubt your sense of direction. The cave's mouth is nowhere to be seen. It's only when you find the scroll from the beginning of your adventure on the ground that you hear the storm outside. You've successfully backtracked to the entrance, but the landscape has changed.
The only exit from this c from this cavern to the shore has been replaced by walls and stellagmites. On the ground lies a chisel of some kind. You could use it to carve some symbols into this new landscape.
A chisel.
Okay, let's take a look at the source code.
Your senses tell you there's something hidden now. You've seen stellagmites before. Okay, so let's check the hidden files.
So we got puzzle nine.
Okay. So, the puzzle's password is Rubicon.
Oh, Rubicon because this is the point of no return.
So, Caesar crossed the Rubicon and he knew that after he crossed the Rubicon, he would be branded like a traitor to the Empire. So, this is our crossing the point of no return. Rubicon.
Good job. You've cleared puzzle 8.
Things are getting a bit weird, though.
Why don't you stop here for today? Stop here for today.
Okay, so this is puzzle 10.
Okay, so we got more family drama stuff from whose journal is this? This is Halibet's journal. Okay, today I remembered something delightful, so I'll write about it and make it harder harder to forget. With the smell of cake in the oven, my nostrils tickled and I couldn't shake the image of her smiling at me. I think of her not only as a model of the perfect mother, but also as the ideal wife.
I know I have dreamed of having a family for as long as I can remember, but I can't help feeling nauseous knowing I basically took over another man's household.
What happened here?
It's not my fault that a woman and a child need the presence of a father. I only wish to help.
Why do I feel guilty when the only one at fault is their absent old man? I'm rambling again. My sweet memories tarnished by sour shame. What would my brother think of me?
Huh?
Okay. Um, that was that's weird.
So, we got um flat stone.
Let's get rid of this one. Actually, there are other flat stones. Flat stone L. So, there's a bunch of flat stones, and we probably need to use them to solve a puzzle.
Here's another flat stone. Although, this looks like an like a video file kind of cuz it's distorted. This one's on this one looks like more even more like a tree.
We've got a mural. So, this looks like some Egyptian stuff.
And we've got some runes above the above the people. So, there's like a moon rune, um a river rune, and like a fire rune.
Okay. So, what's this going on here? The moment you start car, the moment you stop carving, the wall before you starts to move as if a small earthquake takes over the cave. The landscape revealed in front of you is now a long hallike chamber. It resembles an auditorium or altar. Its features seem designed by humans, yet shaped by regular erosion. At the center, you find an empty stretch of space surrounded by unordered piles of stones. Engraved on the ground, you read the following message.
When the path towards truth is unknown, nature will lead me through stacking stones.
You wonder if something is missing here.
There is an there's also a detailed mural on the back of the room, and you can't shake the feeling that it's hiding a different story. So, I think I might have to take the images of the stones and do something with them.
Let's take a look at the source code.
Should you take this advice literally?
You've been finding strange flat stones around the cave.
Okay, so we've got Let's take a look at the different flat stones and put this away. Oh, we can't put it away.
All right, so we'll go through the different stones we found.
Where do we see start seeing these stones?
So, the right door, the left door, etched wall.
Yeah.
Flat stone. So, here's one. So, this one looks like a leaf. This one looks like a tree.
This one looks like a This one looks like a This one looks like a leaf that's been that's been dried out. I'm not sure.
Fishbone. Yeah, I guess it could look kind of like a fishbone, too. Yeah.
Check for hidden files.
Flatstone S. We found it. Flatstone M and Flatstone L.
I need to check all of these folders for hidden files.
No escape.
So this has the image of the of the waves.
So puzzle nine flatstone L mural.
So, were we supposed to arrange these stones in some sort of order?
This looks like it might fit.
These two images look like they might fit together.
H.
I don't think there's anything else we can do to these files, though.
So, we need to figure out some sort of word.
So, unordered piles of stones.
The source code says, "Should you take this advice literally? You've been finding strange flat stones around the cave.
We also have this mural over here. So, it's like one of these is the moonstone, one of these is the river stone, and one of these is the fire stone.
So maybe this is supposed to be the fire stone.
This is supposed to be the I have I'm not too sure what order they're supposed to go in, but I think they're supposed to spell out a word.
What can I do for you? Okay. Don't you love computers? Beep.
We love you, too. Okay. I mean, we can't ask for hints here, huh?
Let's check Let's check the um the files for another stone. Maybe there's one more.
Thank you very much, Mikey B, for subscribing on YouTube. Thank you.
So, we'll just go back to So, the puzzle puzzle one, puzzle two, puzzle three, puzzle four, puzzle five.
Puzzle six.
What? What is this? I know you saw me.
Um, that's kind of scary.
I know you saw me. And there's this uh like moon this moon rune thing here.
Flatstone S.
Okay. And there's stagmite formations, the Rubicon, Flatstone M, which is this one here. And this is the dead end.
MSL.
Oh, you know what? The last time we looked at these stones, there was um with for one of the the image files, there was something inside of the metadata.
So inside the properties, author desktop explorer.
So this is flatstone m.
Let's see if we can locate the other flat stones.
So, what are the properties of this one?
I know you saw me.
Flatstone S. So, this one here. Let's take a look at the properties.
And the last one is Flatstone L.
Whoa. What? There was another option.
Compress with file flattener.
Huh. Okay. I guess we should compression aborted. Current user does not have permission to edit one file in this current selection.
One file in the current selection. File flattener.
The funny thing is that we never really saw this option in for the other image files. So, if we go back here. Oh, we can compress it. Oh, okay. Okay. We can compress all of these image files.
Although, I don't really know what it does.
Okay. So, we'll go back to the altar.
Flatstone L properties and the mural.
It'd be nice to be able to finish this last puzzle before before moving on, huh?
So, Flatstone L is This is a weird file because it's it's an image file, but it also looks like something weird. Some uh there's some um weird filter on it.
We can't really click into this or anything.
Okay, here are the properties.
Maybe we can duplicate it.
So when we duplicate it, it's the same file.
Dragging these on top doesn't do anything.
Okay, let's reread the hint.
So his features are designed by humans but shaped by regular erosion.
At the center you find an empty stretch of space surrounded by unordered piles of stones engraved on the ground. You read the following message. When the path towards truth is unknown, nature will lead me through stacking stones.
Oh, we need to stack them. We need to put them on top of each other. I mean, the easiest way to do it would be like biggest biggest stone then second biggest stone then smallest stone or like stack it like this.
Does this form like a word?
Okay, the images are stacked on top of each other.
So, should you take this advice literally? You've been finding strange flat stones around the cave.
Stacking stones.
You wonder if something is missing here.
There's a detailed mural at the back of the room. It's hiding a different story.
Okay, so the mural is this one.
It's got a flame, some squiggly lines, and this moon looking thing.
Joseph Elliot West says, "What is this?"
This is a It's a game called Desktop Explorer, and the name of the game is at the very at the top of the overlay on the left hand side.
This is just like a warm-up for the stream. Um, we'll be moving on to another topic in just a few minutes.
But this is a pretty interesting like um it's been a pretty interesting game so far. It's just that we can't figure out this puzzle.
So, it's like this guy's spearing the fish, this person is accepting the fish, and this person is doing something to plants. So, plants over here, and then the river thing, and then the So if we stack them like this, maybe stack these both on up.
Here's a fish.
Something tells me that this lines up with this one here. Here. And then this one lines up with this thing and this lines up with this thing.
But apparently that's not what we want.
So if we're stacking them horizontally, there's only a few different configurations we can do.
Hello. What can I do for you? Uh, system tip. We can get tips.
You know a window is focused when its header is colored. This way you can always know which window is on top of all the other ones. Get another tip. You can open a maximum of 10 windows at a time. Memory doesn't grow on trees. You know, trouble reading note page files.
You can zoom in the text by clicking on the view menu. Okay.
Yeah, I'm stumped. If um if anybody has a clue as to what we should be paying attention to, let us know. Can we delete this?
So this is flat stone L.
Every time we try to use the file flattener, it doesn't work.
I guess we can compress any one of these files, but I guess we uh No hidden files.
Let's go back and see if we can find one more.
So that's the installer.
Example puzzle. There was one here.
Let's go. You found the password.
Password 1 2 3.
Okay, we have a some sort of treasure file here. What is this? Oh, nice.
Okay, just an example. Nothing to see here. All right, let's um let's put a pin in this and we'll come back to this some other time. Okay, let's get out of this game.
shut down. Are you sure you want to shut down the system? Okay, so this is this is the demo version of the desktop explorer game. I'm sure you can get it yourself if you want to. And uh well, the demo is free.
It seems like there's a lot of stuff.
There is a lot of stuff to uh to explore in this game. What the heck? I'm uh Looks like I'm getting spoiled. Let me close the window.
All right. So, let's put an hour on the clock and I'm going to be doing a demonstration of a room over at Try Hackme called Kenobi. So, while we do this, I'm going to put on some music in the background.
If the music's too loud, let me know.
Okay. And the room is over here. We're going to be slowly moving through.
Dosski, hello. Nice to see you here. Is this live or is this a recording? Uh, no, this is live. Hello.
Yes. Yes is the answer. Okay. So, if we haven't done this room before, let me reset the room.
Okay. So, we're going to demonstrate how to do this network hacking exercise.
And for this exercise, I'm going to be I'm going to be using a VPN connection.
But if you don't have access to a a Linux a security um dro of Linux to do the uh to do the attack, then you can always use the attack box as provided by tryhackme as well. But since it's a lot easier for me to use my own system, I'm going to use my own system.
So I'm just going to connect to it over here.
And this is the key I'm going to be using.
Okay, QVQ, hello. Nice to see you here.
What is up? All right, so we're connected now. And what we're going to do first is we're going to start up the box on task number one, deploy the vulnerable machine. So, lab machine. Start the lab machine.
Okay. and we should be able to access this in about a minute or so.
Okay, we'll also answer the questions.
So, make sure you're connected to our network and deploy the machine check.
Scan the machine with end map. How many ports are open? So, we're basically walking. Well, I mean, they tell us exactly what we need to be doing. So, it's it might be easier if we just work through the task that they give us and we can answer the questions at the same time. So the next question is scan the machine with end mapap. How many ports are open? So we need to wait about half a minute for the IP address to be shown to us.
In the meantime, let me change up my overlays cuz they're out of date.
So we're now doing topic number two and topic number three is on deck.
Okay. Where's our IP address? Here it is. Okay. So, I'm just going to copy the IP address.
Then, we're going to check our connectivity.
So, we would typically do like a ping.
So, we ping uh we give it two pings and we give it to a specific IP address. So, it looks like we are connected because we got ping packets back or we got a response.
All right, let's go ahead and run end mapap.
So what we're doing here is we're checking for open ports and services on the remote server at this IP address right here. So end mapap we run it very verbose to get us output before the scan finishes. We scan all the ports with -p dash. We scan for versioning information and run common scripts on whatever services we find with the dash uh lowercase s capital c capital v and we run it fast but not too vast with the uh timing parameter here t4. So when we run the command, it's going to let us know that a bunch of different ports are open, including 139 22 80 111 445 and all these other ones. So not all of these are commonly used ports, but we'll talk about some of the more common ones in just a sec. How many ports are open?
One.
Well, 1 2 3 4 5 6 7 8 9 10. That's 10 ports.
Okay. Scan the machine with end map. How many ports are open? Wait, we found 10, but there's only one room for one digit here.
I'm going to have to run the scan again.
We can only run. Yeah. H Okay, let me run the scan again.
139 isn't in order. It's first. 139 isn't in order.
So it hints it it um run it without P.
Run it without dash P.
NAP IP end mapap ip VVV.
Maybe we're only supposed to be scanning the the common ports. So for if for scanning it only for only common ports, we need to get rid of the dashp.
So that's 1 2 3 4 5 6 7.
Is that the answer I was looking for?
That's the answer I was looking for.
Okay. Common versus all. Yeah. Yeah. All right. So task two, enumerate samba for shares.
So, Samba is the standard Windows interoperability suite of programs for Linux and Unix. It allows users uh allows end users to access and use files, printers, and other commonly shared resources and companies, internet and internet, and it's often referred to as a network file system. Samba is based on common client server protocols of server message block or SMB.
Okay, so um this is what I'm going to do. So we know that there are SMB ports available on the machine. So there's uh that's going to be your port 139 and 445.
We can connect to this using SMB client.
So let's go ahead and use another tab SMB client.
We're going to try to log in or access the the service without a valid username and password. Let me just switch out the IP address.
Whoops. Not this round.
Okay. And the first thing we're going to do with SMB client is try to list out the file shares with the -ashl.
Okay. So what do we find? We find there's um there's an anonymous file share and that's probably what we want to access. So we can access that with the the same program SMB client but we have to specify the the file share like this 139 changed three times and with different syntaxes it might be useful later on. Yeah h we'll take a look at it in a little bit later. Okay so we're now accessing the anonymous fileshare with SMB. There's log.txt.
Let's go ahead and download that. So, get log.txt and then afterwards we'll read it.
So, this looks like some configuration files.
This is probably like the Samba configuration file, but they're also creating SSH key pairs.
Oh, this is FTP.
Okay, so this is an FTP configuration file. So, pro FTPD uh file transfer protocol.
So, this is on port 21. So, we probably want to check this out as well.
Okay, but before we do that, let's answer some questions.
So, using the end map command above, how many shares have been found? I mean, I'm pretty sure we found like three file shares.
Okay, once you're connected, list the files in the share. What is the file that you can see? We found log.tx. txt Supreme Overlord. Hello, nice to see you here.
Log.txt.
You can recursively download the SMB share 2. Submit the username and password is nothing. Okay.
Open the file on the share. There are a few interesting things to be found.
Information generated for Kenobi when generating an SSH key for the user.
information about the pro FTPD server.
What port is FTP running on? So the common port for FTP is 21.
Okay. Your earlier endmap port scan will have shown port 111 running the service RPC bind. This is just a server that converts remote procedure call RPC program numbered into a universal address. When an RPC service is started, it tells RPC bind the address at which it is listening. And the RPC program number it's prepared to serve. So in our case, port 111 is access to a network file system. Let's use end mapap to enumerate this.
So network file shares.
So we're talking about um mounting well sorry accessing network file shares. So we can go ahead and run this end mapap scan over here.
And it looks like we found a volume called var.
So this is probably the var directory on the Linux remote server maybe.
Okay. What mount can we can we see it slashvar can gain initial access with protpd.
So proftpd is a free and open source FTP server compatible with Unix and Windows systems. It's also been vulnerable in the past software versions. Let's get the version of ProFTBD. Use netcat to connect to the machine on the FTP port.
What is the version? So, I mean, we can also try figuring out the version of the um of the service using our end map command.
So we'll run it only on port 21 which was the FTP port and end mapap was able to tell us that this is protpd 1.3.5.
So we'll submit this as the answer.
Okay. So we can use search exploit to find exploits for a particular software version. Searchloit is basically just a command line search tool for exploitdb.com.
So how many exploits are there for protectp running? So what we would do is we would go over to use a tool like search exploit which is a command line interface for exploit db and we're looking for profttpd version 1.3.5.
We find that there are 1 2 3 four different exploits for this particular version of the software. So the answer is four.
You should have found an exploit for protpd's mod copy module.
The mod copy module implements site CPFR and site CPTO commands which can be used to copy files and directories from one place to another on the server. Any unauthenticated client can leverage these copies these commands to copy files from any part of the file system to its chosen destination. We know that the FTP service is running as the Kenobi user from the file in the share and an SSH key is generated for that user. So, I mean, I think I know what we're doing here. We're going to copy Kenobi's private key using the site CPR, CPFR, and site CP2. So, copy from and copy to.
Okay. So, So the command is site copy from /home Kenobi.
SSH ID RSA.
So I'm just typing this out cuz uh we have to run these on um on FTP.
So, we'll just connect to the server.
So, just do FTP and then the IP address.
Okay. The name we can log in anonymously.
Hm.
Send your complete email address as your password. I guess we need to log in again. Anus testmail.com.
Login correct. Login failed. Are we supposed to log in with anonymous anonymous?
Hell ghost. Hello. Nice to see you here.
What is up?
Send your complete email address as your password.
Apparently, it doesn't accept that.
Anonymous.
Yeah, it doesn't let us log in. That's weird.
Okay, let's take a look at the exploit.
So, the exploit they were talking about was this one over here.
Uh, mod copy remote command execution.
Let's try. Well, I mean, we could also use the one um that Metas-ploit uses as well. Just hit enter. I think I I think I tried it, but we'll try it one more time.
Yeah. So, the it doesn't log us in.
Try anonymous and no password. Yeah, we just uh we just tried that. Let's try let's try using the the metas-ploit module. So this gives us an opportunity to use metas-ploit which is you know like a really memey kind of well I wouldn't call it memey but uh people like to meme on metas-ploit because it was supposed to be like like a hacker like a hacker super tool.
We started up with MSF console.
Okay. And let's search up that particular thing. Uh pro FTPD 1 point what was it?
135.
Okay, proft mod copy execution. So we'll use that module. So we just need to use use zero.
Okay. And defaulting to command Unix reverse netcat H.
Okay. So what is it about this module here?
So, HTTP port, HTTP port, FTP port is 21, and we're looking for absolute writable path.
Okay, this module exploits the site CPF frT modcopy commands. Any unauthenticated client can leverage these commands to copy files from any part of the file system to the chosen destination. The copy commands are executed with the rights of the protpd service which by default runs under the privileges of the nobody user.
Okay. So we will let's just well we need to supply um an Rhost which is the the vulnerable URL sorry the vulnerable IP address over here.
Set our hosts this thing.
And I think with that we've got all of the stuff that we need, right?
Okay, let's see.
Failure copying PHP payload to website path directly directory not writable.
Hm.
Let me take a look at my notes. I'm pretty sure I've done this I've done this machine before and I think I wrote some notes for for this.
I didn't write very many notes for this, unfortunately.
Okay, let me let me take a look and see if I did anything on my uh on my GitHub.
H. Nothing here. Okay, we'll take a closer look at the um at the walkthrough over here.
Okay, we're now going to copy Kenobi's copy Kenobi's private keys in the site CPFR and site CPTO commands.
So, apparently they're they're just connecting via netcat, not using not using the um not using the FTP client. Okay, let's let's try that then.
Okay. And they want us to use this command.
Okay. File or directory exists. Ready for destination name. So they do what?
site copy to var ID RSA.
So this is the command here.
Copy successful.
So var idsa. So it's in that directory now. Thank you very much. Immortal um Immortal for subscribing with Prime. Thank you very much. Let's uh let's give you a fun video redeem. How about some Jurassic Park?
>> It's a unique system. I know this. It's all the files of the whole park. It tells you everything.
>> Thank you very much, Immortal. And uh if you want to do some if you want to support the channel, you can subscribe with Prime just like Immortal did. Uh there's a there's a YouTube video that teaches you how to do it over here.
Okay, so the file is copied now. So I'm not super sure how this helps us out right now, but I guess we can take a look at the uh at the walkthrough. So, we've moved Kenobi's private key to the var temp directory and let's mount Oh, yeah. Right, right, right. We need to combine this with the fact that we've got we've got access to the to the var file share.
So, we want to make a file mount. So, make directory mount Kenobi NFS over here. I mean, we can just get get out of here.
Okay. So we need to because this is a in the mount directory we need pseudo permissions to do this.
Okay. And then we can mount the system.
So mount our the IP address var to mnt Kenobi and FS.
So like this.
Hold on.
Did we mount it?
Mnt.
Okay. Apparently, we didn't mount it.
Let's run the command again, but we'll run it with pseudo.
Okay. So now there's still nothing here. H Oh no no no. Here it is. Okay. We just needed to wait. Okay. So the the private key should have been copied over to var temp.
So we've got it here. ID RSA.
So this is what we're going to be using to log into the system as the Kenobi user.
I mean, we can we can just make our own copy of this.
So, we'll create a file called ID RSA.
We'll paste in the contents.
We will give it different permissions because these permissions are way too loose for SSH to accept. So we need to do chmod 600 on ID RSA.
From here we'll try to directly access the file system by logging in as the Kenobi user. So SSH Kenobi.
Let's get that IP address.
SSH Kenobi at this provide a key file ID RSA.
Do we want to continue connecting? Yes.
Now we're logged in. Okay.
So, who am I? We're Kenobi.
And I guess we can call in just for fun, we'll call in Mr. Scary Hacker Voiceman to to to talk about how we got in.
Hey there everybody. It's me, Scary HackerVoice Man. Scary hacker voice man comes in every time we break into a system. And we just broke into this one.
Well, Mr. Kenobi administrator, it seems like you enjoy anonymous SMB fileshare access as well as network fileshares that are unsecured and insecure versions of FTP software on your server. These all put together are some big mistakes.
We managed to combine all of these security flaws to steal the SSH private key for the Kenobi user and then use it to log in. Maybe you knew about these security flaws in your system. Or maybe you decided to accept the risk. Well, you accepted the risk.
And now now we're in.
Okay. So, Supreme Overlord says, "Why 600 for the CH mod?" So, CHOD uh runs with um let me explain this.
The chod command can be used with either letters as parameter values or it can use um octal.
You can use what is it called like octal values for file permissions.
So when we're talking about octal values for file permissions 777 is total read write and execute access for all users.
So the first the first number here is the file owner. The second number is the group and the third one is for global uh global promotions.
You must have watched a lot of Mr. Robot.
Uh well I mean I've I've watched the the series maybe twice.
Okay. So when we're talking about 600 600 this means read slash write for owner and no access for anyone else.
Okay 6= 110 and read write permissions for owner group and world. Yeah. So we need to we need um read and write access for only the owner when we run it on the SSH private key otherwise SSH will not accept it. So 600 is read and write access for the owner.
Okay. So we're in and we need to elevate our privileges and we also have our our user flag here that we can read.
Okay. We can submit this.
Okay. What is Kenobi's user flag?
Okay. And we've got path task number four. Privilege escalation with path variable manipulation.
Okay. Let's understand what SUID, SGID and sticky bits are. So let's see the the SUID bit executes files with the permissions of the file owner. The SGI bit executes files with permissions of the group owner. And the sticky bit is is is no meaning. Users are prevented from deleting files from other users.
Okay. So SUID bits can be dangerous.
Some binaries such as password need to be run with elevated privileges as it's resetting your password on the system.
However, other custom files that could have the SUID bit uh set can lead to all sorts of issues. Thanks for the explanation. No worries. No worries. Um it can be a little bit confusing at first, but this is it's pretty normal um inside of Linux to search for a system.
So, they give you a command that you can use to locate these SUID binaries. But generally what I do is I run kind of a different command.
So I look for perms minus 4,000 to dev null hold on.
So, perm. Perm.
Oh, sorry. It has to be perm, not perms.
Make sure you spell everything correctly, folks.
That was a typo.
And when we do typos, we've got a special emote over here. The shine 31 typo.
Like that.
Okay, so we've got Espin mount NFS. That's weird.
So um mount pseudo su mount new grab.
So, one thing that one thing that's good um for these kind of exercises is passing in these this list of SUID binaries to something like the AI. It might be able to help you out cuz AI is very good at parsing through lists of data. So we could ask are there any insecure binaries in this list of SUID binaries.
Okay, pass it in.
I don't have access to a runtime system here to analyze the exact list for SUID and security. Can I outline how you can access it and point to common patterns?
H. So, you're not helping me is what you're trying to say.
Okay. Maybe I can pass this over to another model. Maybe we'll try chatbt terra.
These are my SUID binaries on my Linux system.
Are there any that could be insecure?
Any odd any odd uncommon entries?
Okay, so here's a quick indicator as you access your list for potential insecurity. What to look for on your list? non-native or unusual SUID binaries, high privilege executables.
Okay. So, it it really doesn't feel like there's a custom vulnerable app.
Okay. Let's take a look.
New UID map. So this could be new GD map and new UID map. These could be um custom binaries. And anytime you've got custom binaries that are SUID, it could be um it could be a problem.
Okay. Which file looks particularly out of the ordinary? So, we're looking for a fourletter a fourletter menu. So, it could be this menu app over here, right?
Okay. Run the binary. How many options appear?
So, let's figure out what this what this file is. So, I mean, yeah, it's an executable.
If we just run the binary status check kernel version if config status check H.
So there are three options we can answer that question.
Strings is a command on Linux that looks for human readable strings in the binary.
Okay. So I think what they're trying to say here, so we'll just exit out of the program and we'll look at the strings in user bin menu.
So when we take a look at what the what the binary is doing, it's actually running Linux commands. So it runs curl i localhost.
It runs youame-r and it runs if config. So if any of these particular um actually I guess we need to hijack the path cuz um they talked about path hijacking. The other thing we could do is we could try to see if there's some sort of um privilege escalation exploit for either curl youame or if config. I'm pretty sure there is one for curl.
So this shows that the binary is running without a full path. So yeah, the other thing here is that it it doesn't show the full file path for user bin curl or user biname. So it's using relative file paths.
So we can combine all of these um circumstances to try to do some path hijacking.
Okay. As this file runs with root user privileges, we can manipulate our path to gain a root shell. So basically, we just need to make a new curl file in our current directory and then add it to the path. So I guess uh let's go ahead and do that. We have no access to the prompt. It's as as stated only. No access to the prompt.
Oh yeah, that's right. That's right. we don't get to run those commands with uh any specific arguments.
Okay. So, we'll just move into the temp directory where we know we can write stuff and we're just going to create a a bash file.
So, we're going to echo out bin bash to a file called curl like that.
Then we'll make it executable. chmon mod 777. We we could also just do plus x for the for the curl file in here.
And then we can run the menu.
Okay, we don't run the menu program yet.
We need to add the temp directory to our path. So the file path is basically uh let's talk about this.
So path hijacking, we're going to be talking about path hijacking in our privilege escalation a little bit later as well, but for right now, path hijacking is adding directories to the list of folders.
where commands can be found.
So normally the path on a system is the the list of directories where the commands can be found. And if we take a look at well if we take a look at like our system over here.
So echo echo path this is the all the directories where the commands are found on my system. So home the shy hat.loc.bin/bin and then user local sbin and then user sbin etc etc. Okay. Lame means lord. Can you hack a CCTV?
I mean potentially. I don't really have any any reason to.
We also don't do anything illegal on this channel. Uh Limz Lord, but hello.
Nice to see you here.
Okay, so we also need to export the path.
So export path equals temp and the previous path.
Okay. You want to learn You want to learn how to hack? Okay, sure.
Check out this um this Reddit this Reddit thread over here. It might help you out.
So, it's like export path equals temp plus the previous path.
So, the command looks like this.
So this will add a directory to the path. So export path equals new directory colon and then the previous path to add this directory only. Well, yeah.
Okay, let's go ahead and run this and then we'll run user bin menu.
So when we run this, it's going to use the the curl file in our current directory which has which runs bin bash.
So when we run user bin menu, it'll try to run curl, but instead it'll run bin bash, which will give us an interactive shell uh as the root user.
Okay, we do if config hold on we do status check.
Okay. And now we're not running as the Kenobi user. We're now running as the root user.
Okay. So, who am I? We are root which means we can we can do this.
>> What are you?
>> I'm system rude.
>> Okay. So the last thing we need to do is we need to move into the root directory where they keep the the root flag for these kind of network CTF exercises.
So, the flag is here. Let's read it and let's submit this to finish the room.
So, if you're not quite if you don't quite understand how we uh how we got our root access and how we did our privilege escalation, let us know in the chat. I'll try to explain better.
Okay, here's the root flag. Done.
Yay, confetti.
Okay. And let's go back.
Okay. Path variable manipulation. This is some uh some old school privilege escalation um methods over here. Okay, so I have a question.
How can you read a person's IP address and know the location?
I mean, you can probably take any public IP address and then put it into like a website like what's myip.com.
Just look up like IP IP lookup uh in Google search and you should be able to find like a website. You can plug in the IP address and they'll usually tell you what area the person's in or at least the country.
Okay, so we're done a little bit early, but that's fine.
We can start we can start the next section the next section of the stream a little bit earlier. Let's just get out of here and let's clean up after ourselves.
Okay. Yeah. IP address. Um, IP addresses usually like associated with specific uh ISPs and they're they usually point to they don't usually get you like exact locations, but they're probably going to be accurate to the city or like the neighborhood where the person's located, but it's not guaranteed.
Okay, let's go ahead and close this up and let's get the the Hacker Frogs after school file for what we're doing Okay.
Okay. So, we'll stop the clock and we will put 60 minutes on the clock here and let me change up my overlays. So, we're now doing topic number three.
Topic number four is on deck.
Okay, so this is Hacker Frogs after school. So, this is a program which teaches people about basic cyber security CTF concepts uh in different categories. This is the course for network hacking and this is the last session for this particular course. So this is the 10th session for network hacking. Let's go over the concepts we covered in the previous session. So privilege escalation what is this thing?
So privilege escalation usually shortened to prives is the act of upgrading the level of access on a system typically through abusing insecure settings or capturing credentials.
So if the user has access to pseudo that is root access with any command there's a possibility of abusing that command for privilege escalation.
There's also SUID binaries which are commands that are run in the context of the files owner by default. Most SUID binaries are owned by the root user and certain SUID binaries can be used for privilege escalation.
We also talked about privilege escalation via kernel exploits. Kernel exploits are hacks that target the lowest level of operations in an operating system. Typically older versions of operating systems are vulnerable to kernel exploits. So usually kernel exploits are some sort of are achieved through some sort of um pre-ompiled like C binary especially for for Linux kernel exploits.
So, in this session, we're going to be talking about privilege escalation via three more methods. And we've got uh ads running on Twitch. When ads run on Twitch, we take a little break.
Let's put on these happy birds. We'll be back in about 60 seconds. I just need to take a break for the ads to run by. But in the meantime, watch these birds.
Okay, let's get back to let's get back to the hacking. All right, so somebody was uh let's catch up with chat.
Lan Laminez Lord says, "Are all your hacking journeys present in your GitHub?" I mean, I keep a lot I keep track of a lot of stuff on my GitHub if you want to take a look at it.
It's over here.
Cipher asked, "Does web development often often pivot into pentesting?" I mean, it can.
If you're a web developer, uh, learning web app hacking is a lot easier because you understand how the systems work, but it's not always the case.
All right, let's uh let's continue. So, today we're going to be learning about three more privilege escalation techniques. We're going to do priv via path hijacking, priv via capabilities, and prevesque via cron jobs. So, let's get started.
So, we're going to be using a specific room on try hackme to learn about privilege escalation. And the link is over here.
Okay. So, the first thing we're going to be learning about is privilege escalation via path hijacking. In Linux, the path variable is a list of directories where the system will look for command binaries.
So for example, if you use the who am I command, Linux will first look in the user local spin directory for the command first, then the user local bin directory, etc., etc., until it gets to the end of the path directories.
So if we locate a privileged script, a command we can run with pseudo permissions or an SUID binary that is using another binary without an explicit file path.
Then we could write it we could add a writable directory to the path.
Then create a malicious version of whatever command is being referenced in the privileged binary or script.
Now when we run the priv privileged file, it will open up a privileged shell.
So let's go ahead and uh take a look at this in action. So Linux privilege escalation.
This one is for privilege escalation path. So this is task number 10.
What you want to do is go to path task number 10 and then start up the lab machine.
I think oh does this okay so launch the lab machine attached to the task to follow along. You can launch the lab machine and access it directly from your browser. Alternatively, you can access it over SSH.
Hold on. Let's go up to the top.
Oh, I'm connected by I'm connected by via VPN right now. Okay, let's let me disconnect from the VPN.
Okay, go back in.
So, there should be like a split screen.
Okay, there should be a split screen option here.
Let me reload the page.
You already have a machine running. By starting this machine, the previous machine will be terminated.
Hold on.
So, this should be task number 10.
Okay. So, I guess I guess we're going to need to connect to it via SSH.
Let me go ahead and do that.
Okay. And then we'll log into the machine as the Karen user. So we need to copy the IP address.
SSH Karen at this IP address right here.
Okay. And the password for this user is I think it was like password 1 2 3 password one.
Okay. So we're now logged in as Karen on this machine. And they're talking about I think they were talking about like um a script in the op directory. No, maybe our home directory.
H or the Murdoch user. Let's take a look at the um at the walkth through.
So if a folder for which your user has right permission is located in the path, you could potentially hijack an application to run a script. So path in Linux is environment variable that tells the operating system where to search for executables for any command that is not built into the shell or is not defined with an absolute path. Linux will start searching in folders defined under the path. So the path is environment variable that we're talking about here and the path is the location of the file. So typically the path would look something like this.
So it would look for command binaries in user local sbin, user local bin, um, etc., etc. Okay, as you can see, this entire this depends entirely on the existing configuration of the target system. So be sure you can answer the questions below before trying this. What folders are located under path? Does your current user have right privileges for any of these folders? Can you modify the path? Is there a script or application that can that you can start that will be affected by this vulnerability? So for demo purposes, we will use the script below. So we will use ah okay. So this is a this is a C program that we're compiling into a binary.
Okay. This script tries to launch a system binary called THM. But he can easily um but this example can easily be replaced with any binary.
Okay. So hold on. I just want to find out where the vulnerable file is supposed to be.
I think it should be located as a file called THM. So we'll we'll try looking for that. So find name THM.
wasn't able to find it. Okay, let's start looking inside these home directories. Flag six. I'm pretty sure we're not looking for that.
Okay, so we've got I think it's here.
So, we've got the thm.py Pi which is owned by root and if we take a look at thm.py Pi import. So it's um this is a Python script. So the Python script is importing OS importing CIS. So it's importing two modules and then it tries running it tries running a binary called THM and then it exits. So the the thing about this particular script is that there's no I at least I don't think there's u there's a binary called THM in here uh on this system. So if we just type in THM.
Yeah. So this this binary doesn't exist.
But what we can do is we can create a THM binary that we can use for privilege escalation.
locate THM like which THM it doesn't exist. So what we can do is we can hijack this script and provide a um provide a path.
So we can move into like the temp directory and we can create a THM binary of our own. So echo into THM and this is just going to run bin bash.
So it's this is basically going to open up a a shell for us. And because it's running as this is a privilege script that is running as root, it'll give us a root shell.
But actually I don't think we can run this directly.
So the Python script here.
Yeah, I don't think we can I don't think we can run this one directly. If we just make THM like um bin bash. I think what we should do is we should do like a proof of concept pseudo L. Uh yeah, we could do that.
pseudo L.
So, we don't have any pseudo permissions. So, what we're going to do is we're going to create the THM binary, but we're going to put in something else like a proof of concept.
So, we're just going to have it do touch touch tmp.
This is a cron job.
Okay. So if this is created by a cron job then we know that we know that the the script is being run on at regular intervals.
Okay. We make it executable.
And so if we find um a file called this is a chron job that's owned by root in the temp directory here then we'll know that it's uh that it's working.
So whose directory was that?
I think it was like home murdoch.
Yeah. So the thm.
Oh, we also need to add the we also need to add the temp directory to the path.
So that's the other part we need to do.
So we will do export path equals slashtmp and then the rest of the path like this.
So this is going to add the temporary directory to the path for for legitimate binaries.
Okay. So if this is running as a cron job by root, we should be able to see something within about a minute or so.
But if not, then we're going to have to find some other way to abuse that script.
So try OS system THM except SIS exit. So basically the entire script is just trying to run the system command called thm.
So I mean can we run it? Can we just run python h? Invalid syntax user bin python invalid syntax. Huh.
So the the privilege escalation script has the privilege escalation script is bugged. That's weird cuz there's incorrect syntax in there.
It should be like it should be shebang user bin Python 3.
So it doesn't run.
Is it Python 2? I mean, it's it's not Python 2, or at least I don't think it is.
Yeah.
Yeah. Okay. Okay. So, I guess this is this is not the way we want to do it.
The other thing we could do is we can just go into that directory and then take a look at there might be I think there's like one other privilege escalation method in there. So, test. So we have this test binary and what we can do is we can take a look at the strings to see if it's run. Oh, they don't have strings.
H and I thought strings was uh I guess it's not universal.
So, what I want to do is I want to I want to inspect this um this test binary.
So, what I'm going to do is I'm just going to copy over the contents of the test binary to our to my own machine.
Okay. So, we're going to copy it over encoded in B 64.
And then I'll recreate it over here.
Okay. And then we'll cat it out and then decode it.
And then we'll run strings from our own machine here.
Okay, so the test So the test binary is running set UID and it run it also runs system tacho. Hello, nice to see you here. What is up? I mean, I guess we could also confirm this on our own end by running tests and it doesn't it doesn't give us any output.
Huh.
Okay, so we know that the binary is using the set UID binary as well as the system binary and set GI binary.
And this is all being done without this is all being done without an absolute file path. So we could go ahead and maybe create our own set UID binary but make it malicious cuz well we always want to make it malicious.
Okay. So we'll just echo out actually. Wait.
Yeah. Well, hold on. Hold on. This is this is better for us. This is better for us because this is a set UID binary.
We know it is because it's got the set UID binary set over here when we take a look at the file permissions. Okay. So, we just need to echo out bin bash to temp set UID.
Okay.
And then we need to give it some um executable permissions. So chmod plus x.
Okay. And then when we run tests, it should run the bin bash command in the set UID binary that we created in the temp directory and give us a root shell.
Nope, didn't work.
Why didn't it work?
H.
Okay. So, what else? What else is this script using? Sorry, what else is this binary using? So, it's using set UID.
It's also using system set UID system and set GD.
Maybe maybe there's one other command that it's using that we can try to hijack.
Uh maybe I shouldn't run this on my own system. Hold on.
So when we just run the test thing, we don't see anything here. The other thing we could do is we could uh let's take a look at those strings one more time.
Can it run srace locally to try to see what it's doing? S trace. I mean that also involves letting it run on my system and but I mean this is from tryh hackme so it's probably not going to do anything malicious probably being the operative word.
So we'd run like s trace.
Okay. And we can see what it tried to access.
So user bin execute user bin test.
It's looking for user bin test.
Huh. That's early stuff is all generic C setup.
Yeah. Um yeah, should be should be.
But anarchist. Hello. Nice to see you here.
So it tries to run user bin tests.
I mean I'm pretty sure like test doesn't exist on this system.
Which test? Oh, there is there is a binary called user bin test on the system.
Let's take a look at the file permissions on that.
So, this is a root owned binary.
Yeah. Yeah.
Can you please tell me the terminal name? So, the terminal name is like Q terminal, QT, QT or Q terminal.
And hello, motivate me now. Nice to see you here.
Okay, so I guess what we really want to do is we want to take a look at this. We can't we can't we can read it.
We can't write this binary. We can't modify this.
So, it's using an absolute file path, but a test if this thing is using like some other like unqued or not like non-absolute file path, we might be able to take a look at this thing as well. So, we'll run.
We can just move it over using the base 64 encoding method.
And then we'll examine this one as well.
I don't know why I just didn't delete the whole thing in the first place.
Anyway, save that out and then we'll remove the one we have already.
And then we will read.
And then we'll run strings.
Huh?
What's going on here?
Okay. F flush. Set local string comparison. Okay. So there's a lot more like C functions.
So I guess what we want to do is we want we could also like do some mess trace in here as well.
Okay. User bin test.
This looks for a user bin test, I guess.
Well, I mean, it's kind of a long shot.
We could also try doing that over here.
So we would like echo out bin bash to temp test.
The first execv is just um the shell launching the program, not something that the program actually does. Oh, really?
So we'll just create our own temp test binary in here.
Then we'll make it executable.
Okay. Then we'll run test.
No, didn't didn't work out for us.
Although maybe what we need to do is we need to do it from the temp directory.
Oh.
Oh, okay. Okay. Actually, we we got the first the the first script to run. So, this is a cron job. We got uh we got the Python script to run or the Python script was run as a chron job and it created a um well the instructions in the THM file in here touch temp this is a crown job. So what we can do is we can do something different here. We can create our own uh bash suid binary.
So with the with some instructions like this. So we would echo out to tempth THM.
So this is a little technique that creates um like a bash suid binary that lets you run it and become the root user.
So it would be like copy bin bash Copy bin bash to temp.
We'll call it root bash.
And then after that, chmod.
What was it?
Sorry, I uh I haven't done this in a while. So, let's see. Linux create SUID binary.
So use the chod command.
U plus S. U plus S.
Chod U.
U plus S on temp root bash.
Yeah. Apparently it's um lowercase s.
So chod u plus s to temp root bash.
And I think that should be it. So the these two commands will create these two commands will create a um an SUID bash that we can use to become rude.
Motivate me now says thank you. I've learned many things from you. I really appreciate the step-by-step guidance. Uh you just focus on you don't focus on yourself, you share the knowledge. Yeah, I mean I'm I'm happy to share knowledge with everybody and people in the chat also share knowledge with me. uh I'm not just dispensing the knowledge, people are also contributing.
So copy bin bash to temp root bash and then make it suid binary.
Okay, so it should appear in about a minute or so. We just have to wait 60 seconds. Actually, there's a break going on on stream right now. Hold on.
Go ahead and watch this bird. We will back We'll be back in about 30 seconds.
I just need to take a little uh water break.
Okay. So, let's see if it worked.
H don't see it yet.
Let's check the the THM binary, sorry, the THM file to make sure that it's got the correct syntax. So, copy bin bash. Which bash?
Oh, it's user bin bash. So maybe we need to change up our command.
Okay, the bird went away. Ronald Sound, hello.
Nice to see you here. Hope you're having a good day.
Okay. And we will wait.
Maybe we'll just try to run the thing.
Or maybe it was the test.
Maybe the test suid binary ran the Python script.
Home. Murdoch.
test.
Yeah, the test suid binary ran the Python script.
So that's why we see brute root bash now. Okay, so root bash, we just need to run /root bash p. And now we're now we're root.
Okay, awesome. We managed to do the privilege escalation technique using path hijacking.
Okay. Can you cat this is a cron job also you check the have you checked the etc d folder? Yeah we should we should take a look at that as well but let's see cat or chron job dash l c chron tab-l I think right.
No cron tab for tan. So it's um flag achieved. Yep. ETA cron d folder.
Well, it' be ls.
And there's nothing in here.
Okay. So, we managed to um hijack the path to do privilege escalation for the first example. So, we're going to do another one.
So privilege escalation via capabilities. So capabilities in Linux are a feature which allows for certain binaries or commands to operate with additional privileges.
So as opposed to SUID binaries or pseudo permissions, capabilities allow granular control over binary controls. So, we can return binaries with modified capabilities by using the get cap command.
And we can feed the list of capability binaries to an AI to discover if any of them are potentially vulnerable. So, let's go ahead and try that out.
So, first of all, we need to go over to the capabilities section of this room.
So, that it's task number eight.
So the first thing we need to do is we need to shut down the current machine.
Terminate this and then go over to task 8 capabilities and start up the lab machine there. So we should see that we've been logged out of the previous machine.
So the other thing so I was talking about uh get cap was it get cap-l oh getcap- r okay getcap- r displays the capabilities of the queried files and we were we ran it with ah so we need to run it on the entire file system.
So this will this will show us if any of the binaries in the system have additional capabilities. Uh but apparently it's a pretty long running command. It's Brody. Hello. Nice to see you here. Hope you're having a good day.
Okay. Did it finish starting up? Oh, you know what? We don't need to we don't need to log in.
Okay, we've got a machine here. Let's give ourselves a bash shell. Much better.
So, get cap- rdev null.
Okay, so it lets us know that these there are these additional capabilities for specific binaries.
So I think the one that we need to pay attention to here is that the homearen vim binary here has an additional capability called cap set UID.
cap set UID means that you're able to you're able to specify which user ID to run as or at least I think so could be wrong but uh like I said if there were any unusual if we get a list of capabilities we could feed this into like the AI but here I think we're just going to ask about the cap set UID uh capability.
So is it insecure if a normal user accessible binary has the following Linux capability set.
So what was it called?
cap set UID.
Okay. Yes. cap set UID plus EP on a normal user accessible binary is insecure because it can let an attacker elevate privileges to root if they can execute that binary and control its inputs. So key points to consider.
Okay. And um I wonder if we can find this kind of thing on like GTFO bins.
Ronald sound says set UID should set the user permission for the file. So you can write a script running with the root UID.
So let's see.
So context capabilities here. So the function is performed by passing the usual per kernel permission checks if the executable has certain capabilities set. So capabilities we are looking for we're looking for Vim specifically.
Vim H.
So, it's got a bunch. It's got a bunch of different uh vulnerable binaries listed, but it doesn't have Pearl. Sorry, it doesn't have Vim.
Vim ping view.
Let's take a look at what the walkthrough has to say.
Okay, we can use the get cap tool to list enabled capabilities.
Okay, so here please note that neither Vim nor its copy have the set UID pit set. This privilege escalation vector is therefore not discoverable when enumerating files looking for SUID.
So GTFO bins has a good list of binaries that can be leveraged for privilege escalation if we set if we find any set capabilities.
We notice that vim can be used with the following command in payload. So what do we have here?
Ah okay. So we can run vim.
We can run vim with the with the python um with python commands to run import os os.et uuid0 os.execute execute bin sh and then reset. Okay. Well, I mean that's kind of funny. Uh anyways, let's uh let's see if we can let's see if we can run this.
Okay. Try the vim name.file and paste the gtfo script for the installer program you have and maybe Python or whatever.
Hold on. Let me see if I Let me just copy down the payload.
Sorry. I wish I could I wish they would just like find give us something that we could copy paste.
Okay, so I copied down the payload.
Let's let's go ahead and paste it somewhere and then we can we can examine it.
Okay, so this is Vim run a command. So it runs the Python 3 function I guess and then the Python 3 function is going to do the Python commands. So import OS OS set UUID0 which is the root users UID os.execute Execute execute command bin sh- c reset and then execute sh.
Okay, we'll try we'll try running the payload to see if it works.
I think I can paste into here, right?
So, the Vim binary is in here. I can't paste in here.
It doesn't let me paste. Oh, what a pain in the butt.
All right, I guess I'll just try to type it out by hand.
Okay. Oh, wow. Really? Cyborg is streaming right now. That's awesome. If she's still streaming when I end, I can raid into her.
Okay. What was the rest of the command bin message.
Okay. So, let's see. Something weird happened. Error detected while processing command line.
So import OS. Hm. Didn't work.
So let's exit Vim.
So we tried to run this.
Is there something wrong with my syntax?
Missing quotes before reset, I guess.
Missing quotes before reset.
H.
So quotes here like this.
Ah, okay. Now it works. So, we we're able to run the Vim binary with the capability set and then get ourselves a root shell.
Yeah. Yeah. Managed to catch our um catcher typos.
Okay. So, we managed to become rude again, I guess. So, we can do this.
>> Who are you?
>> I'm system rude.
Okay. So, we'll do one more privilege escalation uh vector. Let's get out of here.
So, this one's going to be cron jobs.
So, cron jobs is a pretty big um is a pretty it's a pretty well-known privilege escalation vector. And we actually did some cron job privilege escalation earlier today.
Okay. So we'll just start this up and let's let's just talk about these cron jobs.
So once a potential vulnerability binary is found, we can check for how to use it for prives using gtfo bins because gtfo bins has a oh it does have capabilities on vim. Hold on. And the last time I took a look at this was like a long time ago. Okay, let's go over to Vim.
So Vim has The funny thing is that Vim doesn't have a capabilities function now, but it used to or does it?
Yeah, this is this is weird.
Anyways, let's go back.
Okay, so this is the this is the section where we talk about cron jobs for privilege escalation.
So privilege escalation via cron jobs.
So chron jobs are a feature in Linux which allows certain binaries or scripts to run at regular intervals. So for example once a minute, once an hour etc etc. So typically the way we would enumerate um enumerate cron jobs is we would take a look at a a specific file called the etc chron tab. Um but there are other ways as well.
So if we would we're able to modify a script that is being used for a cron job or if we're be able to modify a component that the cron job command or the script uses, we could potentially escalate our privileges.
So let's go ahead and take a look at what's going on on the system over here.
So cat etc chron tab.
Okay, so these are the cron jobs that are being run. So the root user is running /antivirus.sh and the root user is also running karen.backup.sh and temp test.py.
So any one of these could be interfered with in order to abuse the crown job and get ourselves some elevated privileges.
So I think the first one we're going to be taking a look at is the home Karen script.
So our user is Karen and Karen has Karen has ownership of the backup.sh script. So we can we can directly modify the backup.sh script to do whatever we want. And we know that it's being run as a cron job by by the root user.
So this is what we can do.
So currently backup.sh is just running these commands over here. So move into this directory and then zip a file. So what we can do is we can just directly modify this file.
Okay. And then we can get rid of what's already here and then put in our own malicious commands. So for example, we could do the the root bash technique again. So it would be hold on which which bash user bin bash. Okay, let's go back in. copy user bin bash to temp root bash.
Okay, that's one line. And then the second line is chmod u + s to make the the root bash executable a suid binary.
And that's it. That's all we need to do in our script. So we'll save it out.
And then if this is being run as a cron job, we should be able to see the root bash.
We should be able to see the the root bash binary appear in the temp directory in about a minute or so.
So let's just check the contents of the script. So, copy user bin bash to temp root bash and then run chmod on temp root bash.
H, not yet.
Well, we'll wait. We'll wait another 30 seconds or so.
But what's everybody getting up to in uh on their Wednesday afternoon or Wednesday evening or whatever time it is where you are? If you're doing something fun, let us know.
So let's take a look at the other right after we abuse privileges with this one. We're also going to be checking out the other the other cron job which is temp test.py Pi, use command watch. Haidider Hadi, hello. Nice to see you here.
Huh? It doesn't seem to be running though.
Oh, you know what? Maybe it's because my script is not executable. It's not executable.
Yeah. Okay. Okay. We need to chod plus X on backup.sh. SH.
So that's the reason why it wasn't working. Or or at least I think so.
Uh I haven't really used the watch command before, but uh how how does the syntax work?
Linux watch command syntax Okay. So, watch options command interval. Set the refresh interval to seconds. Differences highlights the differences between successive updates.
Default monitoring. So, watch.
monitors disc usage using df command with the default settings.
So you would run like watch with.
Okay, so it appeared. So we can run root bash. So we managed to abuse one of the one of the chron jobs. So we'll just run temp root bash with the -ashp to become the the root user. So we're now the root user which means >> who are you?
>> I'm system rude.
>> Okay. So I guess the other thing we can do is we can abuse the other cron job which is which is test.py pi and we notice that test.py is it it just is it just doesn't exist. So if we lsla temp we see that test.py is not in this directory. So we can just create our own test.py in the temp directory. So move into temp and then nano test.py.
So test test.py Pi we can we can also run like system commands using uh using this Python script. So we would like import OS and then OS dot what was it?
OS.System the name of that function os.system system Python function.
So it's just OS.system.
Okay.
So just run OS.System and then whatever commands we want. So it'll be like well we can do the same thing. We can create the root bash. So user user bin bash to temp python bash.
Okay, so that's one command and then we can do a second command which is the chmod one chmod up plus s on temp python bash.
Okay. and then save this out. I'm pretty sure these are the correct commands. Okay.
So, we'll exit out of here.
Then we'll move into the temp directory.
So, after about a minute or so, we should see a Python bash binary get created.
So let's see. Let's try the watch command. So watch watch ls-d.
I think that's the So every two command every two seconds l-d look for differences.
Okay. So, we'll give us another like 5 minutes.
Hopefully, we can uh let's take a look at that cron tab again.
Testpi. So, temp run temp test.py.
I'm pretty sure that Python scripts don't need to be made explicitly executable for them to run.
The other thing we might want to do is we want we might want to go into uh test.py and then add the shebang bin user Python 3 and add this so that uh the system knows which Python 3. Yeah. User bin Python 3.
Okay. So, I mean, if this is being run as a pron job, it should be it should happen pretty soon.
Is the clock correct?
Okay. Where's that chron tab?
So the cron tab says it that root runs all of these temp test.py.
Maybe we do need to make it executable.
Should we go to docker labs?
Uh yeah, I just want to get this last one done. So let's just make test.py executable.
Changing permissions of test.py operation not permitted. Oh, hold on.
Hm.
Oh, I can't do it because because I'm the Karen user.
K actually doesn't actually use shebang lines because it runs things with sh and not bash. Oh, so I guess it doesn't matter then.
I wonder what's I wonder what's going wrong cuz there should the um the root bash file should have been copied already.
So my my my theory is that there's something wrong with the syntax in the Python file.
So, as it's running the script as temp temp.py, not Python 3 temp, temp.py, I think we'll just run it as a shell script and not a Python program. It'll run it as a shell script.
Oh, it won't run a Python program.
Well, I mean, if that's the case, then we just need to go in and get rid of all this stuff. So, if it's running it as a shell script, then we just need to do it like this.
But it we can't make it executable.
Um, so add shebang bin bash.
Okay, I think it will be launched by SH file name, so it doesn't need to be executable.
I mean, I've run into problems with this stuff before. Let's just become the root bash the root user for a second.
Okay. And then we'll just exit from root.
Okay. Just like why can you run python 3 file.py. It doesn't need to be executable. So as noted sh doesn't support shebang lines. That's a bash thing.
Okay. So, everything we'll see in about a minute whether or not the test.py script is actually being run by the cron job. So, if test.py is actually being treated like a shell script, then this should work.
As long as I didn't make any spelling errors.
Yeah. Okay. So, it was created. So, the Python bash, you're right, anarchist.
You're right. And when you're right, you're right. Okay. So, let's go ahead and uh So, the last thing we do is we run Python bash, which is like a root bash kind of thing to become the root user. Awesome.
Okay, so that's the last time.
>> What are you?
>> I am system rude.
>> Okay, so let's review the stuff that we uh that we learned today.
So summary, let's review the network hacking concepts we learned in this workshop. Privilege escalation via path hijacking in Linux. The path variable is a list of directories where the system will look for command binaries.
A systems path can be used as a vector for privilege escalation if privileged programs use other commands without explicit file paths.
We also learned about capabilities.
Capabilities in Linux are a feature which allows for certain binaries or commands to operate with additional privileges.
capabilities can be used for privilege escalation if the capabilities are given to certain binaries or commands.
And the last thing we took a look at is privilege escalate escalation via cron jobs. Chron jobs are a feature in Linux which allows certain binaries or scripts to run at regular intervals once a minute once an hour etc etc. If we're able to modify a script that is being used for a cron job, or if we're able to modify a component the cron job command or script uses, then we can potentially escalate our privileges.
Typos are the bane of hackors. Coffee and keyboards do not mix. Reading is not optional for hackors. Nope. Nope. What's next? Okay, so the hacker frogs after school network hacking course is done.
Tune in next time. and we're going to be looking at a new topic, reverse engineering. So, what we're actually going to be doing, we're not exactly going to be looking at reverse engineering first. We're going to be taking a look at the the low-level languages that are used in both reverse engineering and binary exploitation, specifically x86 assembly and C. So, we're going to be learning how to use those programming languages um well, the basics of them in the context of learning cyber security topics.
Is that not what we learned? Well, we we learned all sorts of things. Okay, let's uh let's go ahead and move on to the new topic. So, the next topic, we're going to go for about 2 hours first and then we'll evaluate from there.
Okay, so we're done with Try Hackme.
We're taking a look at Docker Labs. So, Docker Labs is another one of these websites where you can download vulnerable machines that you can hack against, but in this case, they're Docker containers, which means you have to have a Linux machine. Well, it doesn't have to be a Linux machine, but it's more convenient if you're running a attacker Linux machine that you can deploy these um Docker containers to.
It's also Spanish. That's correct.
So, I mean, we're international here at Hacker Frogs.
Some um some Spanish language hacker material isn't going to get us down.
Okay, so this is Gotham. It is an easy It is an easy machine. And let's take a look at the description. So, I guess we're going to be talking about um JWTs, command injection, password reuse, etc., etc. Let's go ahead and download the machine.
Okay. And we will click on download. So the great thing about these Docker machines is that they're not very they don't have a very heavy footprint. So this machine is only 102 megabytes which it makes it ideal for people who don't have very much storage space.
So this is in our downloads directory now.
And I've got I've got way too much stuff in my downloads directory.
What did they name it? It was like Gotham, right?
Gotham. So, we're just going to unzip this thing.
Okay.
So, the other thing we have to understand about these machines from Docker Labs is that they come with an autodeploy shell script.
So the auto deploy shell scripts well I mean we can we trust docker labs because we've done a lot of other machines from docker labs but because this is a shell script we should probably be a little bit cautious about running it especially for the first time.
So, if you take a look at the autodeploy script over here, we need to understand that it's not running commands that are going to do harm to our computer.
If you're a bit paranoid, but you don't want to go through the whole rigma roll of going through the script line by line, we can always feed it to an AI.
But then again, you you're trusting your computer system safety uh to the AI.
It's all up to you. It's up to you how much how much risk you want to take. So, is there any malicious commands in this shell script?
Paste in the script.
Short answer, there isn't an obviously malicious command, but the shell contains actions that can be risky if run unintentionally. destructive docker operations. Below is a concise review of what it does. So basically what the what the shell script here does is it starts up a docker container with the same name as whatever you supply in the argument.
Uh I think it's like gotham. So we would run autodeploy with gotham.tar Aar and we have this wonderful asciard over here.
IPS this. So, what we're doing right now is that we've got a we've got a Docker machine that's running on on our on our own system that we can access via this IP address. So, if we copy it, we can start scanning the machine and um figure out if we can successfully hack the machine. Anarchist says it's also worth remembering that Docker files have a certain amount of control and escaping Docker isn't too hard. So consider trust of the docker source treating it like running a program on your actual machine. So the other thing well I mean this is another reason why we run our attacker machine as a virtual machine.
So then in case that something really bad happens to our attacker virtual machine, then we're relatively safe unless there's some sort of um is there's some sort of VM escape, which is not not very likely.
Anyways, run end mapap on the IP address to figure out what we can attack on the box. So, we got port 80 and we got port 22. So, port 22 is remote uh shell access. Port 80 is unencrypted web pages.
Anarchist says if you run Kelly in a VM uh then not much risk, but uh don't do your banking on your Cali box. I would never I would that's a that's a very bad idea.
Yeah.
Okay. So, we've got we have an unencrypted web page that is running on this particular on this particular machine. So, we can access this through our web server.
So HTTP this IP address Gotham Net secure access terminal. Okay. So username password authenticate.
So this is just a login page.
Test test test.
Okay. Access denied invalid credentials.
Okay. So, another thing we could do is we could try taking a look at todo remove the temporary guest guest account before going live.
We um well, so this isn't something that's super common. Uh, but sometimes developers will leave little comments on their web pages that they should delete before they um they push it to production.
Okay. So, guest guest, huh?
Okay. And now we're in. So, Gotham Net Control Cashboard. Welcome back guest clearance level user. So network operation center admin and sign out.
Your clearance does not grant access to the knock admins only. Okay. So this is dashboard.php.
So if we try to access admin.php, it says forbidden administrator clearance required. So, I mean, if we've got guest access, we probably were given a cookie when we were given our um when we were given our guest access. So, if we took a look take a look at their web developer tools, we can see there's um session there's a cookie called session.
Let me see if I can copy that session cookie.
So we see that our session cookie looks like this. And there's a very strong indication that the that the session cookie is actually a JWT token.
Sorry, a JWT not token because of um this this pattern right here. So this is a pattern. It looks kind of like it might be B6 C4 encoding.
And what we can do is we can check.
So we can copy this. We can use a common web app like jwt.io and we can paste in our cookie.
So we'll just paste it in. And this confirms that this is a JWT, a JSON web token, which is very commonly used for very commonly used for for modern um for modern web application cookies.
Okay. So, type JWT algorithm this thing uh claims breakdown user guest ro user.
So, what we can do is we might be able to we might be able to what is the word spoof spoof the contents of our cookie uh by replacing the word user with the word admin or administrator. So we can go over to JWT encoder in the same tool and we're going to modify user to admin.
Okay. And it generates this JWT over here.
So we can copy this. I just need to make sure that this is not the same value.
Let me copy paste uh over here.
Yeah. So this is not the same value as the previous cookie.
So what we can do is we can go into the application and we'll replace the value of the cookie.
paste this in and then reload the page.
Uh, looks like it rejected that cookie cuz we got logged out.
Okay, so the other there's a bunch of different things we can do with JWT hacking.
Let me see if I can take a look at my notes.
So, I'm pretty sure I did a bunch a bunch of JWT labs on Portswigger, but I don't know if I recorded them or not.
Okay. Depending on what is allowed, we could set the algo to none and just make up our own JWT.
Uh, do you something like Cubes OS where everything is a VM? Everything is a VM.
Cubes OS. I'm not very familiar with that.
There were also like a few picof exercises that had to do with uh okay so what if we change the algo to none so if we change the algo to none and we give the same stuff over here let's see if we can if we can fold the So, first we'll try logging in as guest.
I'll go to none. No signature. Yeah. So, this is one of those uh one of those attacks. Where is it?
one of those attacks that only works if the system is insecure.
Okay, so it looks like this one didn't work, but there are a few more tricks we can uh we can put up our sleeves. The other thing we can do is we can try to we can try to brute force them a proper key out of it because most of the time these JWTs are signed with a key.
Let me just get the walkthrough for a challenge that might be similar to this.
So that's uh maybe the Joff the Joff challenge. So JWT manipulation the ALG none vulnerability. So the ALG none signature bypass vulnerability. So we've done we tried specifying alg none and roll to admin but this didn't this didn't quite work.
So the other thing we could do is we could try doing some uh brute force. So we can try to crack the we could try to crack the hash for for the key.
Hold on. Okay. So, we'll go back into the application. We'll um authenticate as the guest user and then we'll grab the cookie.
Okay. And then we will echo out to JWT dot cookie and then we'll try to we'll try to brute force the password.
Let me see if I can find something in a previous writeup.
Oh, I did do these. H Just a second everybody. I just need to take a look at um Okay, I did another I've previously done another uh challenge called what is it called? J scratch pad from Cyberlabs or Scilabs.
This one over here. So, which challen which um event was this from? This was from Pico 2019. Let me look at my notes.
Okay. So, JSON web tokens tampering with the token cracking the secret key.
So this is this is why we need to take good notes when we do cyber security stuff because otherwise we need to re we need to retach ourselves how to do stuff like cracking cracking u secret keys for JSON web tokens.
So we can crack the key with John the ripper. So John jwt.txt and then word lists user share word list rocku.txt.
Um, yeah. So, we can try using John the Ripper to crack the crack the key.
So, this would be Well, I mean, I guess we could call this like fuzzing or something, right?
And we found it. Okay. So, Batman Batman, the key is Batman. All right.
Let's go back to the encoder.
And I think the this key was originally.
Let me copy paste the token again.
Okay. Then we'll go back to the encoder and we have to select our secret. So the secret is the is the key and it's Batman.
A key of 256 bits or larger must be used within HS 256 as specified on something something. But I mean it still lets us it still lets us encode it though.
So we'll specify ourselves as admin.
Okay. And then we will copy this. We'll go back to the Gotham web app, paste in the cookie, and then reload.
Okay, we didn't get logged out. And it says we're the admin user. Now, let's go ahead and go to the network operation center.
Administrator clearance required. Okay.
So, it doesn't it's not admin, it's administrator. Let's go ahead and let's go ahead and change that.
So, not admin, but administrator.
Maybe we need to change the role as well.
So, roll user to roll admin.
Okay. And then we've got this cookie here. Fresh out of the oven.
Okay. And then reload the page.
Awesome. So clearance level admin now.
So we can go over to the network operation center.
And then we've got a um we've got a something that looks like it could be vulnerable to OS command injection.
So connectivity check utility enter a host to ping. So target host is I don't know let's ping let's ping our host. So on on the Docker network, we're this IP address.
Okay. And then run diagnostic.
Yeah. So we do have connectivity to our own machine. So we'll run this and then we'll try running the who am I command and then comment everything else out afterwards.
And we're the WW data user. Okay. So, um I think we've got a way in because we have because we have uh remote command execution on the target. Let's talk about what we've done so far.
So on this box, we found a website with leftover guest credentials in the landing page comments.
So upon login with the guest account, we found that our session cookie was a JWT and there are methods of hacking JWTs to spoof them.
in the context of other users.
So in this case, we're able to crack the signing key of the JWT using John the Ripper.
And then we were able to spoof the admin users JWT using the stolen signing key.
So upon on access to the admin panel, we found that it was running a a ping tool that uses OS commands or Linux OS commands.
Okay, we were able to get arbitrary arbitrary command execution using a common OS command injection payload.
Okay. And that's where we are right now.
So the next steps we need to do are maybe we could do something like upload a reverse shell binary to get direct access to the machine. So this is how we would do it.
So what we want to do is we want to create like a local host.
We want to create a local host service that the victim machine can download from.
But before we do that, we want to use a tool to create a malicious binary to upload.
In this case, uh, we're going to use like MSF Venom.
And when we use MSF Venom, we want to make sure that we are where's our Docker?
We want to make sure that we're using the right IP address for our attacker machine because the msf venom command is going to create a connection back to our attacker machine from the victim.
Okay, so we've got our reverse shell binary here, reverse.f.
We will we'll now host the file using the Python HTTP server module.
Okay, so we're now hosting this directory and all the files inside of it so that we can use the victim machines um download functions to download the reverse.f binary to the victim machine.
Okay. So, we'll run we'll run the pin command and then we'll run which which w get cuz we want to figure out which um commands we can use to download the the malicious file and wget is one of the more common user bin wget. Okay, so there is a wget binary on here. The the thing about um Docker binaries, sorry, Docker containers is that Docker containers very often are completely stripped out of every every command and every binary that it doesn't need for its function. So it's often that you're not able to find very common utilities like wget on these docker containers aka every useful feature. Yeah, kind of xedrick. Hey, hope you're having a good time. So we're just going to w get http our IP address.
Yeah, having a good time. Good. Good. So we're going to download reverse.elf.
Okay. So run this command. It should download the reverse.f from our Yeah. So from our web server over here, get reverse.f.
So it should be on the target now.
So, the next thing we want to do is we want to make sure it ended up in the in the directory.
So, this is the current directory. Um, reverse.
There's also robots.txt. That's funny.
Okay. Next, we will give the command chmod 777 to reverse.f self to make the executable executable. Make it executable because otherwise it wouldn't be.
The last thing we do is we run reverse.f.
Uh but before we do that, we need to start up a listener.
So what we would do to start up our listener is we would do something like Penelope.
So, we're going to run the the Penelope shell handler, but we're also going to wrap it with the RL wrap. But I I hear that Penelope doesn't need RL wrap.
What we want to we want what we want to get from RL wrap is the ability to do like history like command history.
Hold on. Let's take a look at the help for Penelope.
Okay, let's let me do a little bit of research.
Penelope shell handler.
RL wrap.
Okay. You do not you generally do not need to wrap Penelope and RL wrap as it includes native readline capabilities and automatically handles terminal resizing.
Okay. So, basic listener OCP safe mode. Use the OCP safe flight to disable potentially restricted automated post exploitation. I actually haven't used Penelope for post exploitation before.
Anyways, uh I'll just run it with RL wrap.
Okay. And then we can actually run the reverse shell binary from the web app over here.
Okay. So when we run that, we see that that the web page hangs, which is a good indication that we've got access.
Awesome. Okay. So, who am I?
RL rap appears to be doing nothing for net penelopey which works for single key presses all the time. Don't you need always read line and possibly no children.
The RL wrapped man page warnings can be sus with um no warnings n so always read line and no children. Um anyways we'll just work with whatever we've got over here.
So, we're WW Data. We want to not be WW Data. We don't have the password for WW Data.
But I guess I guess we can call in Mr. Scary Hacker voice man for the second time to talk about how we got into the system. Let me remind myself first.
Okay.
Hey everybody, it's me, Scary HackerVoice Man. Scary hacker voice man comes out every time we break into a system and we just broke into this one.
Well, Mr. Gotham administrator, it seems like you enjoy leaving guest credentials on your system as well as insecure keys for your JSON web tokens. These are a big mistake. We were able to combine these vulnerabilities and then log into the system as an administrator. From there, it was trivial to be able to find the OS command injection application that you laughably coded and then we used it to upload a reverse shell binary. Maybe you knew about the security flaws on your system. Or maybe you decided to accept the risk. Well, you accepted the risk and now now we're in.
Okay. So, let's go ahead and figure out how to complete the complete the room.
Where are we? Here. Okay.
So, the first thing we might want to do is we might want to take look and see if there's any optional software or files in here. It doesn't look like there are any. The other thing we can do is we can take a look and see if there are insecure permissions in the home directory. It doesn't look like there are any insecure permissions here, but there's um there's a user named Bruce, so we might want to keep an eye out for mentions of Bruce.
And another thing we could do is we take a look at um SUID binaries. So SUID binaries, we're talking about them earlier. So we would do find slash permus 4,000 to devnull like this. And we see that we've got very typical very typical um SUID binaries. I'm pretty sure none of these are insecure.
Okay. So maybe we can take a look at the web page.
Maybe config.php php.
There's also a jwt.php.
So this is basically talking about the how the JWT tokens are created.
And I wonder if the key is mentioned here.
We stole the key previously. It was like Batman or something.
It's not mentioned in the the PHP code though.
So, config.php might have credentials in here.
Oh, Batman. Yeah, Gotham. Of course. Of course. Okay. So, the the database here is called Gotham DB. Arkham Knight is the password. This might be Bruce's password, which I realize now is probably Bruce Wayne because um because it's Batman, right?
So, we'll switch users to Bruce.
Paste in the password. Okay. So, the same password that was being used for the database was um the one used by the Bruce user here. So, pseudo L for Bruce.
And Bruce can use as root with no password user bin find. So user bin find I'm pretty sure is pretty well known on GTFO bins.
We've got pseudo permissions with with the fine binary and we want to do get a shell.
So this executable can spawn an interactive system shell and we've got pseudo permissions with this. So this function is performed by the privilege user if executed via pseudo because the acquired privileges are not dropped. So we just run find exec bin sh and then quit. So it seems pretty seems like a pretty easy payload to understand.
So run find in the current directory and then also run another program. In this case we're not going to do sh but bash and we're going to run that with pseudo.
So here's our payload.
We're going to go into the system.
Paste it in. And this should get us root access.
And now we're root.
And you know what? This is very relevant now.
>> Who are you?
>> I am system root.
>> Cuz you know, we're Batman and everything.
Okay, so we're now the root user. We'll just waltz on into the root directory.
and we'll read the root flag.
Um, I mean, I'm not really I'm not super interested in reading the root flag. I'm more interested in um I'm more interested in the education experience. So, let's go ahead and write a little let's do a little write up for this machine. It was an interesting machine.
Uh, we combined a bunch of uh concepts.
So this is going to be a walkthrough for an easy machine on Docker Labs Gotham and Gotham.md.
Okay, so the URL for the challenge is something the concepts we need to understand to solve the box and the method of solving the box.
You know what we might be able to do? We might be able to go back to the desktop.
We might be able to go to the desktop explorer game cuz that that was a lot of fun. Um we need to figure out what the puzzle was over there. Okay, so the URL for this challenge is over here. I'll just copy the download link.
Oh, there also writeups for this. Ah, there are a lot of write-ups for this.
Okay, here's the download link.
Okay, the concept for this box was JWT JWD hacking specifically JWT um signing key signing key cracking.
Okay, so the other concept for this was also reused reused credentials.
So reused credentials as well as pseudo find I guess.
Okay. So there are want to rate my LinkedIn. I mean I'm not very good at rating LinkedIn I'm afraid.
Mr. Faroke NR Farooq I'm not too sure how to pronounce your name let me know how thank you okay so there are three there are a few different um phases we went through here so our initial like beginning scans there was our so beginning scans into initial access and then privilege escalation.
I mean, a lot of people use uh a lot of people use LinkedIn. Let's not be let's not be too mean.
Okay, so beginning scans.
So, there are only two ports open.
So there's port 22 and 80 on the landing page of the website.
So on the landing page of the website there are there are guest credentials in the in the HTTP comments HTML and HTML comments.
We use these to log in.
And we find there is an admin panel for there's an admin panel that we can't access.
Okay. And we also find that our session cookie for the guest user is a JWT.
So do we call this initial access? This is an initial access. I guess initial access would be after we get access we get access to the admin page.
So we are able to crack the JWT's signing key using John the Ripper.
Okay. And we'll give the command over here.
It's not super complicated.
Okay. Um, with the key and a web app like jwt.io We can spoof a cookie for the administrator user with admin access.
Okay. Create your own website to impress employers instead instead and get a cool domain name. That's uh that could be a pretty fun thing to do.
Okay. So for for our initial access portion um admin dashboard has a has a ping a ping function that uses OS commands in its operation.
Giving this payload confirms that it's vulnerable to OS command injection.
So like Something like this.
Okay. And from here we can upload a reverse shell.
binary and get direct access to the machine.
Okay. So for privilege escalation there is a config.php file in the web directory.
that contains a password for the database for database access.
There is also a Bruce user We combine these two to get access to the Bruce account.
Okay. And then um the Bruce user has pseudo permissions.
with the fine command which is a well-known vulnerable vulnerable binary when combined with pseudo when run as pseudo.
Okay. And then we'll just give the payload to get root access.
This one.
And that's it.
Okay. Done.
Okay. Hey, we might play we might play a little more um of our puzzle game cuz we're uh cuz we're finished early.
All right, let's uh so everybody, if you came here um for the for the hack and content, thank you very much. Uh well, we're going to take it a little easy uh cuz we finished our exercise early. Once again, we downloaded the machine from dockerlabs.es. Yes.
You're not getting addicted, are you, Shy? No, no, no. Not addicted. It's just that um when I see a puzzle that I can't solve, I want to solve the puzzle. Uh that's all. That's all. Okay, let's uh switch our topic back to the first one over here and let's start up the game.
That's what addicts say, too. Yeah.
Yeah, that's what's that's exactly what addicts say.
Okay, let's start up the game.
So, how long are we are we going to try solving this one puzzle? Right.
If we can't if we can't solve the puzzle in I just need one more hit. Maybe a small one.
Yeah. Yeah. Yeah. Okay. So we'll start our demo continue.
So this is basically a puzzle game that's that revolves around accessing somebody's old computer. So in this case, the old computer is running a fictional OS called Next OS and we're logging in as our as our uncle's account. So our uncle Hal, otherwise known as Halibet, left a bunch of puzzles for us to solve.
And it also talks about a lot about trauma because apparently there was some sort of family trauma that happened here.
Okay, so the wall before you starts to move as if a small earthquake takes over the cave. The landscape reveals it resembles an auditorium or altar. Its features seem designed by humans yet shaped by regular erosion.
So, at the center you find an empty stretch of space surrounded by unordered piles of stones engraved on the ground and you read the following message. When the path towards truth is unknown, nature will lead me through stacking stones. Okay, we've got ads running on Twitch right now, so I'm just going to take um a little break to have a bit of water.
Okay, we're back.
You wonder if something's missing here.
There's also a detailed mural on the back of the room and you can't shake the feeling that it's hiding a different story. Hiding a different story. Okay.
So, the mural that um that we need to take a look at is this one.
There is a So, there's symbols. So, this guy spearing the fish has this flame looking symbol and it looks kind of like Oh, okay. And I see that the the files are actually named Flatstone S for small, flatstone L for large, and Flatstone M for medium. So, small, medium, and large. We're supposed to do something with these with these files to get a password.
So, can we see like a small, medium, large scale over here? So, maybe this is large cuz this person seems bigger than the rest of them. And this person seems to be small cuz they're crouched. And then the medium person is this person.
So, small is on this end, large is on this end, and medium is over here.
This looks almost like this looks like it might fit together.
If you have any suggestions, people in chat, if you have any suggestions, please let us know because I and if you've played this game before, if you could give like a subtle hint, I'd really appreciate it because I've been I've been stuck on this puzzle for I don't know like 20 minutes already, and I'd like to be able to get on with the rest of the game.
The lower rock, that lower rock seems to almost match up. So the lower rock match up here.
Maybe we need to stack them like this.
So stack one on top of each other.
Ooh.
Okay. Something happened.
Balancing the stones crack something inside them. Okay, let's uh zoom in.
We're already zoomed in. Balancing the stones crack something inside them. They crumble instantly and reveal some sort of quartz short shards inside. You hold the piece next to your eyes and notice the most interesting qual qualities.
Depending on the angle, it changes colors like a prism in the light. Is this what the inscription meant by truth?
Even the mural on the back of the room looks clearer behind the quartz. Its sigils shine in different colors.
What are we supposed to do here?
Oh, we've got a program. We got colored lens.exe.
And we've got some funky music.
You can hear the music, right? Just checking.
Okay, so stack stones, I think.
So, here's the mural stack stones alter.
So, we we've already looked at this mysterious ports. We just finished looking at this and then we'll run colored lens.exe.
Color me impressed. Colored lens has been added to your installed programs.
You can access it through the start menu programs.
Okay. Start menu programs.
Color lens.
So, are we supposed to filter none? Red, blue, yellow. So, the red Uh, this is scary.
So, this person's on fire.
Okay.
And this person is upset. And this person's upset.
Okay. We'll try some of the other um colors as well. So, blue.
Blue.
This person is scribbled out. This person is upset and is crying tears onto a crocodile.
And this person is also is also crying into into the water.
Okay. And there's one more color lens.
It's yellow.
So, in the yellow lens, we've got some sort of energy sphere.
And this person is asleep. I don't know. And this person is having a good time.
So, this is unaffected.
Okay. So, what are we supposed to do?
We're supposed to look for some sort of password.
Some mysterious quartz. We forgot to look at the um at the source code for this.
So, it seems you'll have to do something slightly different to exit this place.
I mean, we've got this new program over here, the color lens. We can take a look at all the other images to look for some sort of password.
So, let's just put the mural away and the stack stones. Actually, before we put the stack stones away, we'll just quickly scan this So this is Oh, okay. Okay. So the color lens lets us know that this is the blue symbol, this is the red symbol, and this is the yellow symbol.
Okay. So, we'll try taking a look at some other some other files. So, go back up.
No escapeimage.
This has a blue filter.
No what? No escape. No escape.
No escape.
Is that the password?
Security question. What animal is bathing in the tears of grief? Oh, we saw this. So, that was the crocodile.
Um, security question. How many eyes are wearing the bliss of acceptance? How many eyes?
Okay, we need to go back to the mural then.
So the bliss of acceptance that's probably the yellow.
So is this bliss of acceptance? Is this two?
How many eyes are witnessing the bliss of acceptance? So we count the number of eyes.
So this is one two three 4 5 6 7 8 9 10 11 12 13. So I count 13.
Incorrect password.
How many eyes are witnessing the bliss of acceptance?
So the bliss of acceptance is maybe this is the bliss of acceptance and it's two.
No, maybe it's supposed to be three.
So this is not bliss of acceptance and this is not bliss of acceptance.
Let's recount these eyes. Recount these ones here. So that's one, two, three. Oh, this is a this is an I2.
Okay. Um, that means that the answer is 14 instead of 13.
Okay, we solved that puzzle.
Oh man. How did the wrath manifest around the person in the boat? How did the wrath manifest around the person on the boat? So, we're talking about raph.
Okay. So, which color was it? It was the red one, right?
How did the wrath manifest around the person on the boat?
Fire.
Okay.
Who is the dead man on the boat?
Wait, this question feels out of place.
This definitely isn't part of the puzzle. Do you know who they're talking about?
Who is the dead man on the boat?
Is it Is it our Is it our father?
Where where our chronolog log.
Okay. So, we've got this underlying story about like our uncle and our uncle witnessed our father burning to death at some point.
Yeah.
Wall eye.
Okay.
Um, this is scary.
You are not supposed to be spoking around. Are you sure you should even be here?
You shouldn't be here.
You do you wish to forget? Guilt isn't good. You hoh.
Looks like my computer crashed.
Uh-oh. This is scary as hell.
I broke it. I think this is the end of the demo.
So, should we should we play should we continue playing? It's Windows then.
It's broken. It's Windows.
Okay. I mean, I had I had I had a lot of fun. I hear that there's uh the puzzles get a lot more difficult later on, but this is this is fun and it's also like related to CTF challenges and stuff.
What do you think? Should we keep on playing this game?
Get the uh get the real version of the game.
How much the is the game? I think it's like $20.
$20 Canadian. Let me uh let me bring it up.
It's currently 10% off. Wow. A whole 10%.
Okay, let me uh let me shut down the game.
So, it seems to be getting pretty good reviews. So, the re the reviews are overwhelmingly positive and it's 2114 Canadian, which is probably not very much in euros or American money.
Um, you know what? I I kind of want to play this game.
I kind of want to play this game. Let me uh let me go ahead and well let me uh let me let me buy the game and then we can keep on going. Just a second everybody.
Definitely does not sound addicted.
Well, I mean this is it's something that uh that qualifies for the live stream because it's uh puzzle games. It's also like computer related stuff.
and go ahead and um buy the thing.
Okay. Red Sly Fox said, "Has ever tried any hacking games on Ste on Steam?" Uh, yeah. Yeah. I've I've played like um what have we what have we played before?
We've played some We've played Hacknet. We've played Greyhack.
We've played hack.
We've played hacknet. We've played greyhack. We've played what was what were some other like really popular ones?
I mean hacknet and gray grey hack are probably two of the most popular like hacking related games.
Um, I've played a little bit of like Watchd Dogs, Watchd Dogs 2 specifically, but it's not super It's more of an an action game with like hacking stuff. Were any of them actually good?
Hacking games are usually not They don't usually They're usually not very good. They're usually not very good.
But yeah, we should be able to start up the game in just a bit.
H.
Oh, it looks like it looks like I'm going to have to start from the beginning.
That's kind of a that's kind of a bummer.
Okay, let me let me hook the game up to the to the live stream. Just a second.
Okay, you should be able to see it.
Yeah, this is about the same as we were doing before. You may be able to move over the save file.
Move over the save file. The save file.
Let me let me go ahead and do a little search.
Okay. So, apparently you can transfer your saved data from using the game's file directory.
H for many players, the full version will simply read your progress right from the demo files. Oh, really? Let me give it a shot.
Okay. The selected language cannot be changed later in the game. Is that okay?
Ah, okay. It doesn't give you the option to it doesn't give you the option to continue.
But you know what? I think we can speed through. We can just speed through uh what we did previously, right?
Okay. So, let me just uh let me just do a speedrun of what we did previously.
Okay, Scazera says, "The new game called Hackhub is decent." Hackhub.
Let me look that up.
Hackhub Ultimate Hacker Simulator.
What kind of stuff do you do in Hackhub's Kazera?
Okay, chronolog.
We started it, didn't we?
Slyborg is raiding with the party of 39.
Clyborg, welcome uh welcome in. I was I wanted to raid into your channel, Cyborg.
But let's give Cyborg a shout out. What uh what's new with you, Cyborg?
I remember you mentioning that you got um you got a job before your hiatus.
What's up? Uh what's up with you lately?
Making stickers for Defcon. Lil Kiaboo.
Hello, nice to see you here. So, we're currently playing a little um well, it's kind of like a puzzle game. It feels like a CTF game. It's called Desktop Explorer.
And I just I finished the demo version of the game, and it was uh it was a lot of fun.
Okay. Psyched. Hey, what's up, man? I haven't seen you in a while, but uh nice to see you here.
Vim Richie, hello. Nice to see you here.
What's up? What's up? Uh not much. Just trying to get back into streaming and studying. How about you? I'm just doing the same old same old stuff, teaching and hacking and playing games every once in a while.
But you might want to you might want to give this a try yourself on on your stream if you u if you're looking for stuff to do.
Okay, desktop explorer.
Okay, we've got a bunch of puzzles.
We can look at different types of files in the explorer. Great.
Okay, so Sykes says, "Uh, life has been kicking my butt, but doing good, though." I'm great. Great to hear that.
And, uh, Sumeriia asked, "What is up with you?"
Just, uh, streaming as usual. Streaming as usual. We're going to be, uh, streaming for another couple hours.
And mostly we're going to be playing this game cuz uh, well, it's a lot of fun. You solve little puzzles, you input passwords and stuff. It really reminds me of like um of some uh CTF challenges.
Okay, for example, we've got these caves, we've got this compass, and then we got these messages over here.
Not addicted. Not addicted. Not addicted at all.
Okay. So, we assume it's the cave's name Fortuna. So, Fortuna is the password for the next level.
And so some of the puzzles are pretty.
Chant my name, O child, and your voice will bear my fire. When dusk surrounds me, Inana lights my path. So I guess the password for this one is Inana.
Okay. He also did not just finish the demo to buy this game. Uh, no. No, of course not.
We also have this sinister looking mascot which is supposed to be some sort of parody of Clippy.
wide papyrus strip. So you wouldn't call it a nose, but what would we call it? Nobody knows. But there lies the answer. So the interesting thing about this particular file is that we can take a look at the word wrapped version of the file.
And if we play around with this, we get the ele.
This really reminds me of um certain CTF exercises. So Ella elephant elephas elephas.
Okay.
Okay. And then we got more detective stuff.
Okay. read between the lines and find the source of the truth. Only then will you crack the code source code. So on these script files over over here, we've also got source code for them.
On your left, you notice that there is a wall that is thinner than the others.
The word salve is inscribed on it. So that's the password for the next level.
Okay, look at you, Mr. Hacker, over here. You're through.
Okay, so there's so there's a key. It says cannot open file contents may be corrupted.
Um, we've got a little narration here.
So, watching all the detective shows has definitely paid off. Passing both of your hands over this cave's wall has revealed it to be different from all the others.
So, you encounter three doors. Two of them lie beside you and the largest one in front of you. Below the central door, there's a yellow key, but you try your luck using it, but the key, but the door won't budge. There's an engraving on the key, but is very hard to read.
So, for this one, there are two images. So, there's a right door image and a left door image.
And if we put it together, it says rename it. So rename it refers to the corrupted file over here.
So we'll rename it.
I think key dot The text files are called NPG files. So we'll rename the this to an NPG.
So it says you hold the key tightly and concentrate. You're very close but you struggle to form a clear a clear image in your mind.
So what we can do is we can rename this from a text file to an image file.
So this is also very reminiscent of like digital forensics challenges.
So every lock base portonus portonus.
Okay.
Portous.
Okay. So the next one.
So, there's also like an ongoing story over here about our uncle. This is supposed to be our uncle's computer and our uncle has some trauma.
So, my doctor suggested that I write about this line by line. So, I'll give it a go. Can we make this Can we make this bigger?
Hm. I guess not.
My big brother died on a rainy day. The rain wasn't enough to smother the flames. I couldn't help at all.
I trembled for hours during that day. My big brother couldn't escape in time. I saw his face and body engulfed in fire.
That thing did not look like my big brother.
This is stupid. I don't need to recount step by step how my brother looked like a ghoul in his last moments. How is that supposed to help me? How is this supposed to end my headaches? I just ruined my morning writing this.
And if I forget everything like everybody says, how is it that I can't forget my brother's withered face? How's that for amnesia?
So apparently what you need to do while solving these puzzles is figure out what happened to your uncle and what his trauma was. So we're Guppy. So our character is Guppy.
I think we're um we're a young woman.
So, this person, Halibet, this is this is her uncle.
But let's get back to the puzzle solving.
Okay. The rock walls of this compartment are completely covered uh by the same etch phrase, dare to say my name.
Who wrote these words anyway? So this is the wall.
Dare to say my name.
And for this puzzle, what we found was if we took a look at the properties of the file, this is some real digital forensic stuff. We see that the author is MMTT.
What that is, not exactly sure, but that's the answer.
Okay. So, there's a scary face and we've got this picture over here. This uh stone.
Is this supposed to be our dad? So, our dad was supposed to have like, you know, died in a fire cuz he was engulfed in flames.
This is pretty scary to look at. We'll just close it up. I know you I know you saw me. Uh-oh.
Okay, so I think we got to about puzzle 11 or so before we finish the demo.
So, what is this files password?
Let's take a look at the at the script.
What in the dark web creepy pasta game is this? It's kind of like a dark web creepy pasta game. Yeah.
Okay, let's So, as you pass your hand through the wall, the thought of a name that you can't pronounce zooms through your mind. You close your eyes and shake your head briefly. As you open them again, in front of you is the darkest passes so far. You delve inside. The torch can barely you carry barely lights your arm while everything else is in darkness.
Okay. Somehow you feel even more capable of really revealing what's hidden in the dark. Vimi says, "I need this game."
Yeah, I mean you can get it on Steam.
It's not super expensive and you can actually download the demo for free.
So what we need to do is we need to take a look at the hidden files.
Keep out. Reaching this point must have required courage, but going past it is utter foolishness. Heed my words and turn back now before it's too late. Sign Cassandra.
So this is Cassandra.
Nothing gets past you. Fishermen have great eyesight, I guess.
Okay. And then we'll take a look at this telagmite formation. So, this even looks like a CTF flag. We've got these brackets over here, the curly braces, and this spells out like Rubicon.
Okay. Flat stone dead end.
So, there's a dead end. While scratching your head, pondering what to do, you hear a loud you hear a loud thunk off behind in the cave. So, if we take a look at the source code for this, the stallagite formation must have a purpose. And it sounded like it might have come from the entrance. So, what we can do is we can backtrack to the previous levels.
What happened to this puzzle? I don't remember these files being here earlier.
Cannot open path. Stuck until puzzle solved.
stuck until puzzle solved. Okay, so um yeah, it's on sale right now. 10% off.
Let's read.
But the landscape has changed. The only exit from the cavern to the shore has now been replaced by walls and stellagmites.
On the ground lies some sort of chisel.
You could use it to carve some symbols into the new landscape.
Okay, let's take a look at some hidden files. We've got puzzle nine.
So the stellagmites here, they form the the word Rubicon.
And we've got another journal entry.
Today I remember something delightful, so I'll write about it and make it harder to forget. With the smell of cake in the oven, my nostrils tickled. My nostrils tickled and I couldn't shake the image of her smiling at me. I think of her not only as the model of the perfect mother, but also as the ideal wife.
What is the name of this? Tab Ball and Hello, nice to see you here. The name of the game is Desktop Explorer, and you can you can buy it yourself. You can actually download the demo for free.
It's got like about an hour of content.
I know I've dreamed of having a family for as long as I can remember, but I can't help feeling nauseous. basically knowing I basically took over another man's household. So, this family that her uncle is living with, um, he's replacing the father or something.
I'm not sure. It's not my fault that a woman and a child need the presence of a father. I only wish to help.
Why do I feel guilty when the only fault, the one at fault, is the absent old man? I'm rambling again. My sweet memories tarnished by sour shame. What would my brother think of me?
Okay, get back to puzzle solving.
So, we got this large stone. We've got a mediumsized stone and a small size stone.
Okay. At the center, you find the empty stretch of space surrounded by unordered piles of stones. Engraved on the ground, you read the following message. When the path towards truth is unknown, nature will lead me through stacking stones.
You wonder if something's missing here.
So, what we need to do is we need to stack these stones. There's a large one, there's a medium one, and there's a small one.
And then something weird happens.
Okay. I'm glad you caught your stream.
Is the game on Steam? Yeah, the game is on Steam. It's called Desktop Explorer.
So, now we've got a new ability unlocked. We've got a program that we can use to look at images through different filters.
Okay. So, we found out that with this lens, we can look at images and it'll reveal extra information. So, for example, the red lens lets us see something different in this image versus the blue lens versus the yellow lens.
Okay. And we need to answer a bunch of questions.
Okay, so the first question is what animal is bathing in the tears of grief?
So when we take a look at the lens over here, we see that there is a crocodile in here.
Okay, next question. How many eyes are witnessing the bliss of acceptance? So, we need to change our filter and count the number of eyes. So this is one 2 3 4 5 6 7 8 9 10 11 12 13 14.
Okay. How did wrath manifest around the person on the boat?
So, if we take a look at the red filter, we see that the person on the boat is lit on fire. Hey, it's an angel. Oh, a biblically accurate angel, maybe.
So, fire.
Who is the dead man on the boat? Wait, this question feels out of place. This definitely isn't part of the puzzle. Do you know who they're talking about?
So, we we guessed that the person on the boat is supposed to be our father cuz we know Wait, which journal entry is it? This one.
Oh, I might have missed one of the entries.
Okay, let me let me look back.
So, there was an extra journal entry that we need to find.
This one.
Okay. I've noticed something. I noticed that I keep writing depressive thoughts.
So, today I will write one about one of my favorite memories. I don't remember the exact date, but this is was the birth of the short-lived angller trio.
Little Guppy's first fishing trip, and she blessed us with endless catches.
We filled the boat so fast that old walleye started singing again. When we got home, we were toasted with pap and baby formula. Oh, how I miss you, big bro. My memory may might falter sometimes, but I won't forget you anytime soon since Guppy has your melancholic eyes. So, we're Guppy.
It's funny how I can't think of us three without using our code names, but I wouldn't have it any other way. As long as our young last breeds, the Angler trio lives on.
So, the I'm guessing that the name of the dead person in the boat is Wall Eye, which I'm guessing is like Wall-E, which is the name of our father.
You're not supposed to be skulking around. Are you sure you should even be here?
And this is where we got to when the demo ended.
So, we need to continue from here.
Press any key to restart.
Huh. So, we're not Halibit anymore. We're supposed to be Maximus.
So, alert enter recover password. What is my favorite dinosaur?
Uh, did we talk about dinosaurs?
Stegosaurus.
What does the first letter of my future school's name stand for?
Uh, I don't know this next OS. Um, future incorrect password profile recovery questions. So, we we have to get out of here. Enter your password. So, admin, we'll try logging in as uh Halibit again.
Okay, a folder was added to the file path desktop templ intro folder has been created. A new chronolog is available for you to write.
Okay, so let's go over to our journal.
Welcome to Chronologue. Select an entry.
Okay.
Okay. Okay. What was that about? Some woman. My uncle's dementia. My father's death. So, I think it has to do with my father's death.
My father's death. Did the game reference it? I mean, it clearly asked me if I knew who was burning up before the computer crashed.
Who would want my uncle to play a game that made him remember such a thing? It It feels pretty cruel.
I never got to talk to my dad, but we had plenty of pictures of him in our house. It's pretty messed up, but I think his face is pretty similar to one in this game. And most importantly, did Desktop Explorer crash the computer right after changing the background and filling it with alerts?
I think I need to tread carefully from now on. If any of the computer files get deleted or corrupted because of this program, I could lose whatever I have left for my uncle. I hope he didn't see what I saw. The faces when the computers crash when the computer crashed. I don't think he would have been able to withstand that.
I can't write on Chronologue whenever I want, only when I'm prompted to do so.
So, was Chrono Hog like this for my uncle, too? Anyways, here it is. I wrote on my journal, happy computer.
Okay, we need to keep on going with We need to keep on going with uh with these puzzles.
You are alone. A tall stone gate stands before you. Undoubtedly, you find yourself now at the entrance of some sort of temple. Torch light lights the path ahead. Your senses have been guided away. Guided you away for d from danger.
So far, however, from this point forward, you'll need more than your intuition to continue. The cave fortuna is unrecognizable even in name. The door reads a new title for this place. Shy.
It's not me by the way.
Okay. So shy h.
Okay, we've got another journal entry.
So this is our uncle's entry. Since I haven't found any files or computer settings to access the other users, my only guess right now is that desktop explorer has something to do with all this. I just unlocked a puzzle that made me install another program called Color Lens.
However, I just read on the NextOS manual that Color Lens comes pre-installed with the computer already.
Is Desktop Explorer hiding things from the computer? Maybe it'll eventually let me access the other users profiles.
I don't know if I'm imagining things, but some of the in-game text kind of resembles what I've been writing in my journal. The puzzle even has an Egyptian mural. My doctor says it's common for people with my condition to overthink stuff. I must remain calm.
Hm.
Okay, let's take a look at the script file. Well, here's our pictures. So, there's a chamber and there's a scarab podium.
All right.
So, there are three paths to exit this chamber, each protected by a stone guardian. An eye on the ceiling oversees this room. It's as if this engraved symbol wishes to witness your decision on how to proceed. Choose wid wisely. A do-headed man oversees path one with the name Anubis below his feet. Um, Anubis below his feet. His stone gaze is a reminder you must your fear of the unknown. An ibis-headed man watches you over path two with the name Thoth below his feet. His stone gaze is a reminder of your weakness to succumb to madness.
A falcon-headed man guards path three with the name raw below his feet. His stone gaze is a reminder of the frailty of the human body. In front of you lies a podium with a metal plate on top. A scarab is depicted on it along with three uniquely shaped holes.
Okay, let's see if there's anything in the source code.
No.
So, I think we have to solve these one at a time.
So, Anubis is is this guy right here. We should probably pull out our lens and see if there's anything hidden in the images.
Okay, nothing for red.
Nothing for blue.
Nothing for yellow.
And I guess this other image doesn't really have anything hidden in it either.
Okay, so no shenanigans here.
So, path one, Anubis. Input the files password. It's not just Anubis' name, is it?
Okay, this should be easy enough. You get this done in no time.
The Eye of Horus has recorded your path decision. Oh, we were supposed to choose a path.
Uhoh.
By passing this threshold, you immediately feel lighter. However, this sensation goes beyond your physical body. You walk on the line between spiritual harmony and eternal despair.
You reach a room surrounded by religious imagery. At the center rests a scale with coins on its plates. The left plate holds a coin with an engraved heart. The right plate holds a coin with a feather symbol. The scales are currently tilted to the left.
So, um, was this Anubis? Anubis like weighed your heart and if your heart was heavier than a feather, then you went to hell or something. I don't remember what the exact tail was.
The scale has a familiar sign sigil engraved on it. Okay, so there's you've learned to reveal the secrets of the moon sigil before. So I guess we will flick flicks I don't know has subscribed.
Thank you very much for subscribing on YouTube. Thank you.
Okay, let's uh let's apply our filter.
So, this is a scale and I think we want to use the the yellow filter.
Ah, Nulk says hell is empty and the devils are here. Where? What is that? A quote from Shakespeare. Okay.
So, 90 kg 90 kilobytes and this is 40 kilob. So, are these files?
So, this is supposed to be the heart on this end and this is supposed to be the the feather. So the feather is 40 kilob and the heart is 90 kilob and we've got this monkeyheaded guy here.
Let's take a look at left plate and right plate.
So there's a heart image here.
So this is supposed to be 90 kilobytes.
Let's take a look at the the size. So the properties 90 kilobytes author halibet. So this is supposed to be halibit's heart and the right plate flat file compression compressed file. So this is like a zip file.
What did that do?
Oh, because we decompressed the file, the fi the size of the file increased.
So the scales are currently tilted to the right. The scale is a familiar sigil. Okay, that's that's kind of clever. So, we increase the the the weight of the f of the of the feather by decompressing the file.
I mean, are we supposed to balance this though?
So, this is 120 kilobytes. This is 90 kilobytes.
Um, So we can either compress with file flattener or we can restore back to the original state.
So here's the coin and we haven't taken a look at this with the um with the lens. So it just looks like a regular thing.
What are the properties here?
So this is also owned by halibit.
Let's try compressing this because I think what that we need to do is we need to make the scale balanced.
So we will compress and maybe we need to compress the heart file as well.
Okay, now the heart file is 30 kilob versus 40 kilob. Can we comp uh double compress this? I know that in real life you can double compress files, but I don't know about this game.
We can only extract.
I mean we can also duplicate.
So we if we duplicate it then the file size increases by twofold.
Duplicate three times and then decompress.
So left plate we'll extract. So this is 90 versus 80 four times text. Hello. Nice to see you here. Decompress the left.
So this is 90.
We can So now this is 120 kilobytes.
Maybe we'll go in here and then we will duplicate this and then we'll compress one of them.
And now they're the same. So a balance frees me from the jaws of EMTT. So the I mean it has to be that has to be the password. Thanks guys. Thanks for the uh for the advice.
Muffin Hawker, hello. Nice to see you here. I'm here. What do you need help with? Uh well, we're just trying to figure out these puzzles.
You reach a room surrounded by religious imagery. The current the scales are currently balanced. Okay, good. Okay, so we'll solve the puzzle.
So, this one is EMTT.
Good job. I thought you would have cleared this one quicker though.
Everything okay? Uh, yeah. Everybody's a critic, huh?
Okay. So, what do we have here? We should probably search for hidden files. No hidden files.
We got dark vines.
got left wall.
These carving on the wall. Haven't we seen something similar similar in the previous puzzles? Yeah, we have.
So, we have this wall and we have these dark vines.
I mean, we should probably take a look at it through the filter, but before that, we'll take a look at the journal entry.
I must never forget this. I wanted to give Little Guppy a stuffed animal at the zoo, so I let her choose whichever she wanted. I tried my hardest to convince her to pick the giant bass plushy, but I think she figured out I was trying to influence her. She's so clever. It was really cute.
She ended up deciding on a small stuffed dinosaur. Wouldn't you know it, of all the possible toys, she chose a Stegosaurus.
It was cute, sure. But I couldn't help making the connection to Maxine.
Who's Maxine? Is that uh our mother?
Must be a thing between tough girls. I hope someday that they can get to know each other.
H who's this Maxine person okay so following a voice clicking on the clicking of the scales triggers an opening on the floor a set of downward stairs is revealed the walls rever reverberate with a spiritual approval of some kind you can't understand and it meaning a slightly flooded floor welcomes your descent.
The rel religious scriptures around the walls are now partially covered with vines and a large sculpture of a crocodile's head rests on the nearest wall. This new room is dark, but you clearly see multiple unlit torches around you.
There is something inside the crocodile's jaws.
Text says, "What what game is this?" Uh, this game is called Desktop Explorer.
It's a pretty new release. It came out this week. You can get the demo for it free if you search for it on Steam.
There's something inside the crocodile's jaws, but opening by force proves futile. On a hunch, you speak loudly.
Abracadabra.
No luck. However, you know that there is power in your words. Scanning the room again, you start to remember something that could work. Okay, let's check the source code.
Maybe a different magic word might do the trick. Do not be afraid to modify files. Oh, okay. We can start modifying them.
Wait, sorry, I didn't hear you. What was again? Desktop Explorer. You can see the name of the game on the upper left portion of the overlay.
Okay. So, the crocodile's jaws.
Ah, okay. So, this thing right here.
We want to open this. So, this is the dark vines file.
Let's compress this.
Can we compress it? We can't compress it. Okay. What else can we do to this?
We can duplicate it. We can rename it.
I can't rename this.
I can duplicate it though.
Can we open up both of them at the same time? Yeah.
H.
Let's try looking at it through the lens.
The yellow one.
I don't see anything here.
So, the blue lens, no.
The red lens, no.
Okay. So, we'll try we'll try going for another hour or so and then we'll uh we'll call it we'll call the the stream.
Let's see how far we can get an extra hour.
Okay. So, dark vines. Let's get rid of this.
Can we compress this? Can we do anything with this other file? So, the left wall one.
We can't compress it.
We can't.
We can't rename it.
We can duplicate it, but I don't know what if that's supposed to do something.
So, there's also like uh numbers.
So, there's 1 2 4 8.
I have no idea what these could mean.
lock jaws.
So, there's power in our words.
What are we supposed to do here?
So, we're told maybe a different magic word might do the trick. Do not be afraid to modify files.
But how can we even modify these? We can't compress these.
I compressed the I compressed this file. I don't know what it does.
Okay, so this is a storyteller. Oh, STP stands for a storyteller. Okay, desktop explorer left wall.
H I'm kind of running out of things to to try.
cuz we're trying to open up this crocodile's jaws using some sort of power.
And it says that we're supposed to modify files.
Oh, you know what?
Maybe we're supposed to grab the the clues from the previous puzzles and then put them into this folder cuz we've got the elephant and we've got the key and we got the cave. There are all these image files.
So, let's see.
There was a picture of a key, right? So, the cave mouth is this one.
Can we actually copy it from one location to another?
We can't really move them outside of here's our dead end.
Here's our stellagmite formation.
Okay. And then here, this stagmite formation has the number eight.
Let's see if we can see something through the color lens, yellow, red.
Okay. Nothing here.
So this is Oh, this is puzzle number eight.
Okay. And this is puzzle number four.
Then this picture of the key from puzzle number four.
Let's check this for possible things to look at.
Nope. Thank you very much for following on Twitch, Pamusi. Thank you.
Okay, maybe we need to have these pictures open. So, 8 4 6 1.
Where's puzzle six?
Ah, right. This scary picture.
This guy.
So, it looks like we need to color lens.
What does it say? Will we meet at the river's end? Do you miss me? That's scary as hell.
Okay. So, that's this this picture. I guess we'll stack all the pictures in one pile like this.
What are we missing? We're missing the the elephant, which is number two.
We'll make this a the white papyrus.
We need to make this into the elephant.
Here's the elephant here.
Okay. And then number one. Number one is The no escape image.
What is this?
Is hack smarter on right now?
No escape.
No escape. No escape. No escape.
Okay. So, is there anything with the the other filters? Nope.
Creepy atmosphere in this game. Yeah.
It's like uh So, we opened all these.
Now, what are we supposed to do?
So, we opened up the the elephant, the the wall, the creepy face, the key, and the stagmmites. Am I supposed to do something with this?
Will you meet me at the river's end? I know you saw me.
Okay. So, somehow we need to modify these files.
Do we need to compress all of them?
Can we compress them?
So, let's see.
So, no escape.
Can we compress this?
No, we can't compress it. We can't rename it either.
Yeah, I'm not too sure what we're supposed to be do be doing for this puzzle.
H I mean, I'll keep these open.
Maybe we'll try doing the other paths first. So, path to top.
Can you modify the images? I wish I could.
Okay, so this one is one of my favorites. Pay attention and don't mess this up.
All right, so The music is kind of scary here.
Okay, we've got a map fragment.
We've got another map fragment.
So, are these supposed to fit together?
We got a mirror.
Okay. And we've got a we have a journal entry. I feel so conflicted. I miss her so much. But I think ultimately she just desired to be alone. Looking at the whole picture, I can't help but to assume the worst. I must latch on to whatever hope her mom still holds. My only lead right now is very loose, but it's the only thing I've come up with.
Max used to go on and on about the CMAA.
Maybe she's fulfilling her dreams of studying art or at least is taking a course there. CMA. So, this is the university.
If she submitted a portfolio or an application, we can track her actively with the help of a private detective.
So, this person wants to stalk someone.
Or at least we should be able to ask around. CMA main page. I'll find the time to do it soon. I've been so busy lately taking care of the baby.
The system ran out of memory. One window needs to be closed. Okay, we'll close a window. How about this one?
Cascadia Modern Arts Academy.
CMAa.
So, Cascadia, that's probably the That's probably the password.
Exchange programs. Oh, this is So, no internet connection found. So, I guess we can't we can't go to any of these pages because we don't have internet access.
Yeah. Okay. Okay.
All right.
So, what's going on here?
We can't we can't uh modify these map fragments.
There's nothing to be seen here using the filter.
Oh, we're supposed to navigate like this.
New file added map fragment 4 and map fragment 3. Okay.
So, this is interesting.
I guess we're going to need to close out some of these to make room for.
So, this is map fragment three and map fragment four.
What's going on here? So, we need to look with the lens.
No, there's a spoiler.
Maybe we need to apply the mirror somehow.
Wait, what's going on here?
So, the mirror says that we're supposed to move from green to red. Move from green to red.
Easier said than done.
Okay. So, we can move to over here.
Oh, so we can move now. Now, how do we get this done?
We have to start at green.
And then can I move this around?
Hm.
Yeah. So, move from green to red. Uh, what else do we have?
So, there's nothing else here.
There's nothing in yellow.
Oh, can we compress this? So if we compress this, does the does the image change?
This is map fragment 3.
I didn't even read this. I should probably do that.
Okay. You go through a cloud of smoke to pass this threshold. Engulfed by the sens scent of incense, your senses are heavily clouded and you feel dizzy. Is your memory failing you? How long have you been here? Did you just arrive? Were you just about to leave?
The room you find yourself in is as puzzling as your thoughts. Countless mirrors cover the walls of the labyrinth in front of you. Walking through it without aid is impossible. Luckily, there are map pieces in one of your pockets.
Were you always Were they always there?
Did you always have pockets?
A clouded mirror is on your is in your sight. It has a familiar sigil engraved on it. Let's check out the source code.
You've learned to reveal the secrets of the water sigil before.
Okay, so we're using water sigil. So, blue.
And this just tells me to move from green to red.
So, map fragment 3. Let's Let's see if we can compress this. Can't compress it.
So, we can't compress any of these.
the properties.
Maybe there's hidden files in here.
Nope, no hidden files.
Yeah. Move from green to red.
So apparently, how do we get We can't get the other map fragments back. Huh?
Is there some way we could resize the window? I don't think we can.
Okay. L I says, "I just finished this game today. Such a fun game. It's decently long, too." Awesome. Awesome.
Good to know that there are other people who are playing the same game.
So, we can move to over here, but there's got to be some way to cheat this.
Oh, we can duplicate these. Okay. Okay.
Okay. Yeah. Yeah. Yeah. Okay. Great.
Great. Great. So, the map fragment 4, we can duplicate this over and over again.
So make one here. Make one here.
Then make one here.
And now we can get to the exit.
Just need to make sure we're going.
My mouse control is not that great.
Hold steady.
Boo.
What a jump scare, huh?
Okay, so now we're given What is this?
So, this shows us some numbers. So 5267 5267 Okay. Wowee. Wasn't that cool? I wish I could just forget it to experience it again.
Okay, so this is the blue lock box. So, we have hourglass, an oldtime tracking device. How antique.
Our modern clock is so much. Wait, why did it turn red? Why did it turn red?
That's a good question. So, we have five and then what is this?
Archaeologist notes. Sure.
Can we make this bigger?
Time seems to have an effect on this room. The hourglass clicks for every hour I've been stuck here. Translating my notes so far have revealed to me this poem.
On a dark night, a blue moon rises while a red eye leaves the sky, leaving a tune from up high.
Plenty blood stained feathers fall slowly to the ground while sapphire scepters rise.
As many as time decides.
When you look closely, sand fortells the path. The sum of all is more important than the value of its parts. Think carefully and you'll realize time takes all but memories. Lastly, I see something written on the wall. A clue of some kind. It says red face equals 48.
But the red face appears when the hourglass marks 12 hours. What am I missing? I don't understand the the sand is rising. Time is running out.
Red face equals 48. But the red face appears when the hourglass marks 12 hours. So do we need to multiply?
So the relationship between 12 and 48 is 4. So multiply by 4.
Okay, so they've got Let me start writing some notes cuz it seems to be a lot of moving parts in this puzzle.
So it's like red eye, blue moon, blue moon, red eye, blood stained feathers, sapphire scepter.
Okay, the sum of all is more important.
So, sum them together.
And red face equals 48.
Red face equals 48. But the red face appears when the hourglass marks 12 hours.
So red face 48 hourglass is 12.
H.
Okay. So five. What is this thing?
So at the base of the hourglass, so this is the blue filter. The red filter doesn't show us anything.
The yellow filter doesn't show us anything either.
Under the blue filter, the hourglass has one, two, three, four, five marks.
Hourglass, five marks.
And oh, so the number of marks is equal to the number at the bottom.
Five displayed at the bottom.
Okay, so we still haven't taken a look at this thing yet.
You approach the mirror to get a clear image without thinking you you pass your fingers through its surface. The mirror bursts into pieces. Every single mirror that surrounded you shatters unexpectedly and brings sand falls upon you.
Look around you in a panic. You spot a dried out corpse next to their old old notes. There is something in their hand, a decorated hourglass. Interacting with it only adds to your confusion. Is your mind playing tricks on you? Time is running out. You don't You do not wish to share their fate drowning in the sand.
Okay, let's take a look at the source code.
You can see the water sigil inscribed on the wire water in the hourglass. Okay, so we we took a look at that.
Okay, this is the first puzzle that starts to ramp things up a tiny bit. it gets way more difficult that well I mean I'm here to get better at problem solving skills. Uh so five so this is five.
Let's take a look at the properties. So this is just called hourglass.
Okay. So this is without word wrap. If we put word wrap on it, then it wraps around. Okay. Right.
Uh, Cipher asks, "Where is this puzzle game?" We can find it on Steam.
It's called Desktop Explorer.
Can we copy and paste?
Oh, we can.
Could we always do this?
And we can we can type in here.
We can also save new files.
Huh? What's going on?
So, the only thing we have is this hourglass image.
There's the number five here. How do we modify the time?
Doesn't look like we can do anything.
We can't compress these things.
Oh, wait. Can we compress? Okay. Can't compress. Can't rename.
Is there something we can do to modify these numbers?
Let's take a look at the notes one more time.
Just an FYI for you because you're using notes a lot. You'll be using notes a lot later on. You can open a notepad in the programs list and save to documents to keep your notes. Oh, that's great.
That's great to know.
So, it says something about blue moon, red eye, bloodstained feathers.
Blue moon.
We can also modify. Can we modify the clock? We can modify the clock.
Okay. Get out of here.
This apparently is 2021.
2012.
It's a long time ago.
Oh, okay. So, this changes between A.M.
and P.M.
Or does it? It doesn't seem to change.
Now it's three.
So, now this is three. But the The time is 8:00 a.m.
Okay, let's let's get a sense for this.
So 8:00 a.m. equals 3 and the mark is scepters.
7 a.m. is 5.
7 a.m. is 5. And the mark is feathers.
So, blue moon, red eye, blood stained feathers.
I'm guessing this is feathers. Then we'll switch it over to 6 a.m. 6 a.m. is 3.
6 a.m.
3. And the symbol is uh a woman's face.
Is supposed is this supposed to be red eye or something?
woman's face. Say five is four with pyramids.
5:00 a.m.
Four pyramids one. So 4:00 a.m. is one moon.
Okay. And then 3 is 6 I 3 am 6 I.
So, there's also the difference between marks on the left versus marks on the right, although I'm not really too sure what those differences might mean. So, 2:00 a.m. is five and scepters.
1:00 a.m. 1:00 a.m. is two in feathers.
No, 1:00 a.m. Yeah, 1:00 a.m.
Okay. And then rolling back to 12:00 a.m.
12 a.m. is four and a face.
Four woman's face.
11:00 p.m. is 1 and pyramids.
1000 p.m. is I just need to record all these. So that's six in a moon.
This is nine.
It's two and an I.
8:00 p.m.
Three scepters 700 p.m.
Five feathers 6:00 p.m.
3 and Woman's face 5:00 p.m.
is foreign pyramids.
Okay, we're getting pretty we're getting closer. So, there's 24 of these in all, huh? Uh jeez.
Okay, 400 p.m.
Are there ways to make money online? Are there still ways to make money online?
That's a good question. I don't know if I can answer that.
Are you talking about like legitimately or are you talking about not legitimately?
3 p.m. is 6 6 I 2 p.m. Where did we start? We started at like 8:00 a.m. So, we need to get back to 8 a.m.
crime. Haha. All right.
So, this is five scepters 1 p.m.
Two feathers.
12:00 p.m.
Four women's face 12:00 p.m. 11 a.m.
Okay, so we've already recorded all these, right?
One, two, three, four, five, six.
Oh, I haven't done uh 9:00 a.m.
or 10:00 a.m. or 11:00 a.m.
Looking into side hustles, but YouTube noise is either get-richquick or harsh truth. Freelancing projects seems to be seems the only give crumbs if you're lucky. I mean, making easy money. I'm not sure.
Okay, so 11:00 a.m. is one pyramid.
And then 10:00 a.m.
is six moon.
wouldn't mind making a fun website or something if it was just a buy me a coffee pay.
I I mean I sympathize.
Okay. And 9:00 a.m. is 2 I.
Okay. So, what were the the symbols?
So a blue moon, red eye, blue moon, red eye, sapphire scepters, blood sand feathers, Okay. So, this is what I've got for the This is what I have for.
This is not very um very friendly to look at.
We need to find some way to come up with a sum.
I see something written on the wall. A kind of clue. It says red face equals 48. Red face equals 48. Wall of text.
Yeah, wall of text.
So, I guess we what we need to do is we need to we need to set the date and time to the right thing.
So we need to sum up.
We need to sum up the numbers.
So red face equals 48. Red face equals 48.
Change it to So the the time never changes unless we hit an hour.
The other filters don't do anything.
Three.
So somehow we need to put in the password.
Blue moon, redeye, feathers, sapphire.
Okay, let's record that one more time.
Blue moon, red eye, blood stained feathers, and sapphire scepters.
So, we've been told that the that the red face is 48.
Okay. But the red face appears when the hourglass marks 12 hours. So if we set the time to 12.
Okay. So this is the red face.
Sorry. This is the red eye. Oh, this is an eye.
So if we change it between AM and PM 4. Okay. And then PM.
So if we change it between AM and PM.
How is this 48 though? So, red eye is 12 a.m. 12 a.m.
So, 12 * 4 12 * 4 is 48, right?
So, multiply by 4.
Could that be it? So, we're also talking about like a blue moon.
Where does When does the blue moon appear blue?
So, here's the blue moon. So, this is It looks like the moon appears at 10:00 a.m. 4 a.m.
10 p.m.
and 400 p.m.
So, if we change between AM and PM here, it doesn't it doesn't change one.
So, 4:00 a.m. and 400 p.m. should be the same thing.
Yeah.
Okay. So, Blue moon. So, blue moon equals 1 * 4.
So, 4 * multiply it by 4.
So, 400 p.m. times. But it says 1.
Okay, we'll go back to 12.
12 is four.
And the red eye is supposed to be the red face appears when the hourglass marks 12 hours.
12. So this is 12.
This is four.
So if you multiply 12 * 4, you get 48.
So multiply the number.
Get red star. Hello. Nice to see you here. We're playing a puzzle game. It's called Desktop Explorer. And it's got a bunch a bunch of puzzles.
Too many in fact. Anyways, we're just trying to figure out this hourglass puzzle here.
Okay, so we want to figure out the blue moon.
So the number, whatever number is here, we multiply it by the time we're looking for blue moon.
So there's the blue moon. The blue moon is 4:00 a.m. So 1 * 4.
So blue moon equals 4.
And then we're looking for blood stained feathers. So I guess how long has the stream been going today? Um well, we're coming up on the 6 hour mark.
Okay, now we need to find blood stained feathers. So, red feathers.
So, these are red feathers. So, it's 7 * 5.
7 * 5 is 35.
And then the last one we're looking for is the sapphire scepters.
So we need to sapphire scepter. So this is blue scepters and this is 5 * 2. So this is 10.
We need to sum up these numbers and then provide that as the answer for the to this puzzle. So this is what I have.
So if you put this together, it's 13 plus 8 12 13. So I I have like a 133 as the sum for this.
And let's try submitting that as the answer.
Incorrect password.
Okay. What do I have wrong?
The sand is rising. Time is running out.
So, we're working at sums.
Blue moon, red eye, blood stained feathers, sapphire receptors, and then take the sum.
Oh, no, no, no, no. We're looking for red eye, not red face. Okay, sorry that uh changes up my my calculations a bit. Uh so let's look for red eye.
So this is the red eye. So this is 9 9 * 9 * 2.
So 9 * 2 is 18. So that changes the sum.
So that's 13 + 5 6 9 10. So that's 103.
Let's try 103 as the answer.
Nope.
Yeah. What do I have wrong?
Two.
So, A.M. and P.M. are both the same.
red face. Okay, let's bring up the red face.
So, this red face, it says 4 down here.
It is 12:00 p.m.
It's supposed to be 48.
4 * 12 is 48.
But what other what other calculation gets us there? Is there anything else?
There are four notches here.
The sum of the sum of all is more important than the value of its parts.
Think carefully and you'll realize that time takes all but memories. So, blue moon.
Blue moon is four. Let me Let's just double check.
So four four should be blue moon.
And this is one.
Red eye should be 300 p.m.
or 3.
No, we're looking for the red eye.
Oh, there it is.
Okay, so the red eye is nine and it says two.
So is this actually 9 * 2 which is 18 bloodstained feathers.
So we should we need to identify which one is the feather. So this is a feather, right?
Bloodstain feather implies red feather. Five 5 * 7. 5 * 7 is 35.
Does it matter if we change the year?
Changing the year doesn't do anything here.
It only cares about the time in the 24-hour clock.
So AM and PM don't matter in this case.
So the last thing we're looking for is sapphire scepters. So blue scepters.
This one.
So 5 * 2.
Okay. So by by my calculations, I sound so nerdy when I say that. This is what it should look like.
So blue moon. Let let me do the let me use a calculator to do the math because you know sometimes my ability to do math is very bad.
4 + 18 + 35 + 10 67.
Did I I did I do the math wrong? I must have. Okay, let's try 67.
I feel so dumb and I can't do math. I can't do math worth a damn.
Tough puzzles. Hopefully those these distractions help you forget other stuff. Uh yeah. All right. So, we've run out of time, but I'm going to read this last part before we move on before we uh finish out the stream.
What is this? Raw ore.
Okay. So, here's this raw ore.
You You hold in your hands a small blue treasure chest. You imagine the possibilities of what could be hidden here. Ancient knowledge, buried truths, or a map for the exit. Opening it reveals nothing but a lump of coal. To say it's a disappointment is an understatement. Whatever this is for, you are certain that obtaining this rock is your reward for clearing this temple's path.
Okay. Is there anything in the source code? A useless rock may perhaps maybe years in the future it'd be worth something. H.
Okay. So, everybody, we'll uh we'll come back to the next time we do this. I'm not too sure when that's going to be.
We'll come back to this part of the game. Okay. So, let's go ahead and get out of here and then we'll talk about what we're doing for the next stream. Okay, everybody. Let's take a look.
So, today is Wednesday and we just uh we just finished up our stream. The next stream is going to be on Friday. So, we're going to be doing we're going to be taking a look at paradoxes with puzzle walkie. We're going to be um talking more about logic puzzles cuz that's something I'm interested in. I'm interested in becoming better at logic.
We're going to be taking a look at reverse engineering challenges over at PICOCTF. Taking a look at um assembly language and we're going to be taking a look at a um well, we're going to be introducing ourselves to x86 assembly. So it is a very very fundamental programming language for computers that use the x86 processor which is a lot of them. The last thing we're going to be doing is we're going to be doing we're going to be trying to do some software security challenges over at all cyber. So this is a combination of reverse engineering and binary exploitation and we're going to see how many of these we can solve in about 3 hours or so. All right. So without fur well let's go ahead and take a look at if anybody is on infosexreams.com.
Okay. So it looks like Blaze Bits and Hacksmarter are both um are both online right now. So I think Hacksmarter has uh given us a lot of raids. So we should probably um return the favor. Let's see what Hacksmarter is up to right now.
x86 is the 36 bit of the op code. 64 is the new 64bit. So it's um the full name of the language that is used these days is x8664 if you want to be uh proper about it.
So hacking active directory in AMA. So if you want to learn about how to hack Windows systems active directory then you want to check out hacksmarter. We're going to raid into his channel. Raid hack_smarter.
Okay. So, everybody, when you arrive at Hacksmarter's channel, please give this message OSROG hiphop hack OSROG.
And thank you very much for coming today. I appreciate everybody who comes to my stream. Once again, we're going to be back on Friday. So, please come back on Friday and we're going to be doing more hacking and more puzzles and more of all that good stuff. All right, everybody. Hacker Frogs out in five, four, three, two, one. See you next time, everybody.
Related Videos

TOP 15 Data compression Interview Questions and Answers 2019 Part-2 | Data compression | Wisdom jobs
wisdomjobs
281 views•2019-06-28

CTS 158: 802.11w Management Frame Protection
ClearToSend
4K views•2019-02-04

NDSS 2019 Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid Fuzzing
NDSSSymposium
496 views•2019-04-02

How realistic is Cities: Skylines?
CityBeautiful
159K views•2019-02-14

GUIs & TUIs: Choosing a User Interface for Your Python Project | Real Python Podcast
realpython
2K views•2025-04-04

The OSI Model - Explained by Example
hnasr
225K views•2019-05-12

Cloud Computing - Introduction
elithecomputerguy
98K views•2019-10-07

From Traveler's Dilemma to Dynamic Routing | Demystifying Networking
IITBombayJuly
5K views•2019-08-04
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23