Privilege escalation in cybersecurity involves gaining higher-level access on compromised systems through techniques like Active Directory enumeration (using PowerShell commands such as Get-ADUser, Get-ADComputer, and Get-ADGroupMember to extract user credentials, domain controller information, and group memberships) and binary exploitation (exploiting software vulnerabilities like buffer overflows, format string vulnerabilities, and business logic flaws to execute arbitrary code or access sensitive data).
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
PRIVILEGE ESCALATION LIVE! PowerShell Hacking & TryHackMe
Added:If you can hear me, type in type in hacker frog dis space issue disc space issues. Yeah.
Okay, we're back. We're back. Okay, great. Great. Great.
Thank you everybody. Um I think we might have lost we might have lost YouTube.
Let me see if I'm streaming on YouTube right now.
No. Are we on YouTube?
YouTube is back up as well. Okay. Thank you. Thank you. That was uh anyways thank thank you very thank you very much everybody. Okay. So let's let's get back to what we were doing. Um I was having some problem with that disc space.
That's kind of that's kind of weird.
Just buffering. what's going on.
Okay, so we can specify like specific uh directories to look inside of. So let's go ahead and do that. So we run get child item recurse hidden file and then we can do like let's see dot slash dot slash there. Now, there's now more than one stream. Okay. Yeah, that's true.
It's a bit of a pain, but uh it's better than not having to stream at all.
Okay. So, what directories are we supposed to be looking inside of?
Contacts, desktop, documents, downloads.
So, it's contacts.
There's a bunch of these, so I might as well keep track of a few different directories that we're looking inside.
YouTube issues. Yeah. Yeah. Yeah. But you know, it is what it is.
Okay. Desktop, documents, downloads.
Back on mobile. Okay, that's great.
Okay. Favorites.
Oops.
Green spider. Green spider. Okay, that doesn't sound very good.
Music and last one is videos.
H Oh, we got we we found one. The other thing about this is that we we had a lot of like error messages. There has to be something to suppress error messages, right?
So PowerShell suppress error messages.
So it's like error action silently continue.
So just run all this And then we just get the secret sauce file. Okay, that's great.
Let's go ahead and let's go ahead and read this. That's the name of the file, right?
So, the password for Century 12 is the name of the hidden file. So, the name of the hidden file is secret sauce. Let's go ahead and uh record our solution for this.
We need to search recursively inside certain directories on the users in the user's home diretory.
Okay, we'll give the command over here.
No Wi-Fi at the moment. Steaming fish.
Steaming fish.
All right, let's copy that. We'll paste it in. This is PowerShell.
And that's it.
Then we can move on to the next challenge.
So the next level is level 12.
So the first thing we do is the SSH command slashpass.
We record the instructions.
We record the method of solve.
Okay, let's get out of here.
So, the SSH command is identical um except that it's century 12 and password is what? Secret sauce.
Okay, the instructions for this level.
Let's take a look.
Okay, the password for Century 13 is the description of the computer designated as a domain controller within this domain plus the name of the file on the desktop.
Okay, let's copy that.
Let's go ahead and copy this.
Oops.
So, SSH as sentry 12 password paste it in.
Okay. So, everybody, if you want to do the same level as we're doing, I'll um provide the SSH command and the password over here.
the description of the computer designated as the domain controller.
Okay, so I guess we could look for PowerShell.
Get domain controller computer to find domain controllers in active directory using powershell. So you do get ad domain controller commandlet.
Okay.
Hm.
So, we're not we're not looking for everything in here. We're just looking for a specific thing in this output, right? We're looking for the description.
So, dash description like this. No.
Description of the computer.
So what is the description?
What is the process? What is the process? So I guess uh maybe what we need to do is we need to specify the host name.
Specify the host name and then We need to get the description to the computer.
40 ounce horada. That's a that's a funny name. Hello. Nice to see you here. Uh is this I am is this I am I mean this is PowerShell and we're currently working inside of like an active directory environment.
Okay. So I guess what we need to do is we need to use PowerShell get computer description.
So to find a computer description via PowerShell, you must use different commands depending on whether you want to query the local Windows system description or the Active Directory object description. I mean, I'm not too sure which one we're doing here.
I am I am Dpril. Hello. Nice to see you here.
Okay. To find the description configuration in the local Windows system profiles local Windows system properties, use the get cim instance commandlet.
Okay. Remote computer append computer name your p your PC name to the command.
Okay. Let's Let's try copying this.
We'll paste it in.
And we also need to specify which computer it is. So, computer name.
And I can't remember what the thing was called.
April says, "I always meant to do under the wire. Over the wire was the bomb."
Yeah. Yeah. I mean, learning how to do stuff in PowerShell is very handy if you do a lot of scripting inside of Windows.
Hold on.
Copy paste is always a bit weird.
Okay. So, what's the computer name going to be here?
Maybe this host name. UTW.underwire.te.
tech.
Or maybe by the IPv4 address parameter cannot be found that matches the parameter name computer name. So computer name this isn't quite working.
So, get ad computer identity your PC name.
Maybe it's going to be the get ad computer commandlet instead.
Snygoster says under the wire was so under underwhelming.
Sniggy, hey, nice to see you here. We're just trying to cover our bases.
by doing some um some PowerShell stuff in comparison to Over the Wire anyway. I mean, Over the Wire's got a lot more variety in the stuff that's there. I mean, they've got they've got like uh Linux war games.
They've got web they've got web app security war games. They've got cryptography war games. They've got um reverse engineering and binary exploitation, but uh Under the Wire just has PowerShell stuff as far as I know anyways.
H.
So, we can't find our description here.
So, we ran get 80 domain controller, but I'm wondering what name we use when we try to query information about this about this computer. Kind of hate PowerShell syntax, but got to admit it's handy. Yeah, I mean, it's very it's very extensible, but uh it's it's too verbose.
Okay, so this thing is just called UTW, maybe.
I wouldn't be caught dead with it on L.
It's not really meant for Linux.
So the identity of the machine is just UTW.
Okay.
Okay. This is exactly what we want.
You can actually uh I don't know if that's the best thing to do on Linux.
Is the description I authenticate?
I authenticate. I authenticate things is the password for the next level.
All right, let's uh let's write about it.
So the first thing we need to do is get the get the details of the domain controller in our environment.
Can't we do that with this command?
Get AD domain controller.
So the identity of the computer is UTW.
We can feed this into the next command.
This one.
So we can combine the description with the the file name on the desktop.
Okay. And then I think we're I think we're finished this with this level.
So the next level is level number 13.
So the whole password is I authenticate things like this and let's get that SSH command.
Okay. So, if you wanted to do this yourself, here is the relevant information.
We'll record the instructions and the method is solved in the challenge.
Okay. So the password for century 14 is the number of the number of words within the file on the desktop.
The number of words within the file in the desktop. This should be pretty this should be pretty easy.
But first, let's go ahead and log into the server.
Okay, count my words. So, count my words.
Is there is there like a built-in word count into files using PowerShell or is there something else that we need to do?
PowerShell get word count.
Okay. So let's see. Measure object commandlet with the word parameter.
So get content measure object word.
Seems pretty straightforward.
GC GC count my words.
Split measure object. Split measure object. Split by I mean split by um by space also seems like a pretty good idea.
But let's see if this works first. So we're going to run it on count my words.
So, measure object word word 755 H.
Let's see if this is the actual Let's see if this is the actual password. So, just get out of here. We'll um double check.
That was That was it. That was it.
I didn't know that there was a word parameter. I mean, you learn new stuff every day, huh? I mean, I do. I'm I've learned I learned dozens of new things every day.
Okay. So, I mean, it's pretty it's pretty straightforward here.
We're just kind of flying through these HMD, hello. Nice to see you here. Nice to see you. Okay, we can move very swiftly on on to level number 14.
So after we if we So this is not super difficult right now, but uh we might come on like some levels that are that are very difficult.
I'm not too sure how long we want to go on with this cuz it might get a bit boring after a while.
So, I think it was like 755, right?
Let's try again.
Yeah. Okay.
And the sh SSH command was this one.
Power shell training for the people.
Well, I mean for the people who want the power shell training. Yeah. Yeah.
Okay. Method. Sorry. instructions.
Let's get those instructions.
The password for century 15 is the number of times the word polo appears within the file on the desktop.
Important note, you should count the instances of the whole word only. So, we need to make sure that Polo is by itself.
Dapel says the people who have to use it don't want to be on Windows.
I mean, I'm sure I'm sure there are people who use PowerShell who enjoy using PowerShell. I don't know.
Okay. So, let's get into this.
So, we're doing PowerShell. We're going to get get string pattern or get word get number of words number of specific word but not as part of a larger word.
I agree. Just there are people who like to self mutilate. Doesn't mean we should just let them. Haha.
Okay. The more you use power shell, the easier it gets. Is quite handy in some respects. I mean, it it is it is quite powerful.
Okay. How do you extract a specific word from a text file?
Select string. Select string command that uses a regular expression matching to search for text patterns in the input of strings and files.
Where am I from? Uh, Canada. Canada.
Yeah.
So, measure word.
All right. Let's let's talk about this for a sec.
Count specific strings in text file using PowerShell. So this is good old Stack Overflow.
Here's one method.
So select string.
So the best the best version that they have of this is like a multi-line file.
So file content equals get content your file.txt txt matches equals select string input object file content pattern export export all matches matches.mmatchescount this does seem kind of uh kind of verbose now doesn't it mean if it works it works H.
Okay. Count polo. So, we're looking for uh the name well the word polo in this file.
So the first thing they've got is file content equals get content your file. Uh for this one is going to be count polos.
And the next line is matches select string and look for the pattern.
Select string input object file content pattern is polo, right?
Isn't that count the chicken in Spanish?
I guess so.
Polo. It's polo without the s though.
The word the number of times the word polo appears within the file.
Okay, so all matches and then we do the last one which is matches.mmatches.count.
We have 158.
I'm not sure if this is the password for the next level. We'll give it a shot.
Yeah, this isn't it. Okay. So, so we need to we need to make sure that the word polo is not part of a larger word.
Okay, so it looks like in this file Snagos says file content split SLS pattern polo something something measure object. What is the what is the dollar sign at the end of polo? Does it mean that it has to be cell content split on what a word list reject pattern? Oh, okay. Okay.
So, file content get content this thing, right?
count polos.
Okay, so Snygoster recommends recommends like file content this thing.
Hold on.
This thing right here.
Measure object.
Count 153.
153.
Now, is this only going to count strings that are on their own?
It means ends with polo. Ends with polo.
How do we um completely isolate it though?
So, SLS pattern in PowerShell isolate isolate string.
If you want to be super specific, you do oh starts with polo and ends starts with P. Okay. Okay. Okay. All right. Let's uh let's give it a try. So start of line start of string this 153.
Okay. So I'll just I'll save this and I'll see if this is the correct answer.
153.
That was the correct answer. That's awesome. That's awesome. That's awesome.
Thank you, Snowing Guster. That uh that was uh that was clutch.
So file content equals something something and then file content.split on spaces SLS pattern our pattern.
Although I guess we could also do like get get content and then like pipe it into pipe it into the split.
I wonder. Let me let me give that a try one more time because it's it's always nicer if you're able to do it in like a oneliner.
Okay. Want to do a king of the hill.
King of the Hill. I don't I don't think I've I haven't done a King of the Hill before.
So let's see if we can do it like on get content count polos and then pipe that into pipe into the split on this and then SLS this pattern.
Hold this thing and then pipe that into measure object.
Ah, okay. So a parameter that cannot be found that matches the parameter named split. So get get content doesn't have split have to wrap it in parenthesis.
Oh, okay.
I like this.
Okay, it does work. Great. Great.
All right, let's let's measure that.
Sorry. Let's um let's record that.
Power shell.
Yeah, they really like to split it on these things.
They're so fun. Uh, if you're not with sweats. Not with sweats. I mean, is it?
Well, it's more fun for the sweats, I guess, if they were doing it. I have a root kit that I made. A root kid. That sounds like a lot of fun. Xmanus, hi.
Nice to see you here. Hope you're having a good day.
But yeah, King of the Hill. I mean, if I was if I was to do a King of the Hill, I'd want to plan it in advance and get like a get like a good number of people on each team and make sure that the the teams are evenly split.
So, this is going to be level 15.
It's not teams, it's more individual. I mean, usually like uh King of the Hill.
Oh, King of the Hill as in everybody's fighting to be king. Okay.
Okay. I thought you were talking about like attack and defend, which is what they do over at Defcon.
Like the Defcon CTF is attack and defend.
Okay. So, there's like a king.txt file and your name has to be in it. Oh, okay. So, it's like a oneon-one. Can you do it like Can you do it like uh like a free-for-all? Can you do it like with um five people or seven people or 12?
Oh, it is a free-for-all. Okay.
Okay. So, what are our instructions for this level?
It can be one-on-one. I guess that would be your uh how to solve how to resolve issues with people in the hacking community. One-on-one me scrub, that kind of thing.
One-on-one me and King of the Hill.
Oh, that's it. This was the last level.
Not my forte. I don't I don't really ever think of how to defend. I would lose hard.
I mean, I I think most people who do like um network hacking exercises would would lose pretty hard on the defend portion, but uh defending isn't just patching. You have to or you just don't defend.
My defense is My defense is offense.
Okay, so level 15 is the end of the game.
Huh. I wonder if we can do another game then. So there's Century, there's Cyborg, there's Groot, Oracle, and Tribec.
Pick a game and then pick a level. 0 to 15. All of these games are 0 to 15.
H I think I think we might just move on to another we might just move on to another um to another thing now cuz I think I might be a bit powers shelled out.
Are they all power shell? They're all supposed to be PowerShell. Yeah, because this entire channel is about PowerShell stuff.
Scroll to the top to see the credentials. After obtaining the credentials, connect to the server via SSH.
I kind of don't want to I kind of don't want to interact with their Slack channel, though.
Maybe the credentials are online.
Hold on. Let's Let's search for this PowerShell. Uh under the wire cyborg cyborg level zero password. All the credentials should be online. I'm hoping so.
The password to log into the initial level level zero of the underwire cyborg post power shell war game is cyborg one.
Okay, it's cyborg one. Okay, great.
Let's give this a try.
Actually, Cyborg Zero is the name of the level.
Has anybody heard from from Slyborg lately?
Let me make sure I've got the SSH Cyborg. Oh, it's it's okay. Okay. I need to change the um the name of the game here as well.
Not in a while. Yeah, she got a she got a job. Um I think it was like a non tech job, too.
Let's see. She did come back once with a stream where she said she got a job and would not stream as much anymore. Okay.
Hm.
Did I not spell this correctly?
SSH Cyborgz at cyborg.underwire.te.
Yeah, Cyborg is a streamer, right? She uh she used to she was like doing um whole like documenting her cyber security journey. She's very popular.
H Yeah, it looks like it's that's not the it's not the correct password.
I guess they changed they changed the credentials.
I think she I think she's still aiming to get into cyber security. It's just that she has to she has to take care of her finances first.
So it's not Cyborg Zero.
H I guess we're going to have to check their slack.
The other thing I could I could cheat and I could look at the YouTube video.
Actually, the YouTube video isn't going to show us the the password because the password is blanked out.
H maybe I can take a look at the at the walkth through just a sec. Just just a bit. Just a bit.
Huh. That's kind of funny.
for needing people. The industry is way too hard to get into. I've decided it's just a hobby. Yeah. I mean, the thing about uh the thing about cyber security is that it's reported that.
Okay. So, the first level is actually cyborg cyborg one and not cyborg zero.
That's interesting.
All right, let's uh let's go ahead and get started. So, this is the end of the game.
Congrats.
Okay, so the next game is Cyborg.
level one.
So the SSH/pass we'll put over here.
They only want to hire people with five years of experience. Sometimes it really does feel like that.
Well, I mean it at least that's the way that it feels like especially if you look at the job postings. The job postings all have like a laundry list.
Yeah, they all have like laundry lists of of requirements for like entrylevel jobs. But the other thing about cyber security is that even the entrylevel jobs in cyber security aren't necessarily how do you spell that? Necessary entry level.
I mean, I guess some of them are like you would expect that like sock analyst level one, this would be entry level, but like network or even like junior network pentester.
This is very rarely going to be entry level because the the required skill set to do like junior network pentester work is way way higher than you'd expect for entry for any entry-level job.
Yeah, soft analyst level one is kind of entry level. The rest do not exist as entry level. I mean if you wanted to do like malware so something like forensics analyst which you would so you would suppose that this was this would be an entry- level job. That's actually not entry level.
where you would go to get like a forensics analyst job is that you would start at like sock analyst and then you would work your way up from sock analyst level one to level two and then maybe you would you would um pivot from there to get into like a forensics analyst role and by entry level you mean something that you can do straight out of school.
Yeah. It's not it's not super realistic.
Like most cyber security, most CISC jobs have a laundry list of um of like prerequisites.
So it's a laundry list of prerequisites, you know, for example, must be familiar with I don't know. Um, anyways, I don't even want to go into it. Uh, it's a shame because Sock Analyst is super boring. Had no heart for it.
Okay, so we've got instructions and we've got method to solve. We might solve a couple of these levels and then move on to something else.
Okay. The password for Cyborg 2 is the state that the user Chris Rogers is in.
I'm sorry, what? The password for Cyborg 2 is the state that the user Chris Rogers is from, as stated within Active Directory. Okay. So, I'm assuming that Active Directory stuff we just need to get the Active Directory user and then look at the details to the description.
We want to get the AD user for Chris Rogers.
Chris Rogers. Okay.
So, we're doing PowerShell like 80 users by first and last name.
Holy grammar. Holy grammar. Grammar.
Grammar. Grammar.
To find Active Directory users by their first and last name using PowerShell, use the get ad user command lit with the filter given name and surname.
So I guess we need to do something like this.
We're looking for what was it?
Chris Rogers.
So this is Chris.
Okay, so we found the guy.
So we found the guy. Now we need to get his user description.
So PowerShell 80 users get description.
So get ad users properties description.
Is this all we need to do?
properties description. This kind I mean sometimes PowerShell really reminds me of um of SQL.
So there's no there's no description.
Hm.
The state that the user Chris Rogers is from as stated within active directory.
State refers to the location within the country and not state of the account.
location within the Wait, are we able to get is there like a location?
Yeah, I mean we we can also get all the properties.
So we can just properties everything.
Oh, okay.
So, it's not a specific.
We're looking for a property called state.
I mean, this isn't normal.
I mean, I don't think this is normal.
Normally, they don't have like a property called state.
Okay. Or a X509. And what is X509 in this case?
Notice it populates there.
I mean, this is all the information here.
TLS TLS. Okay. Okay. TLS certification or Yeah.
Okay. So, I mean, we've got the command.
We'll do a couple more and then and then we'll uh re-evaluate.
and it said property state. It popped up. Yeah. I mean, I'm not sure whether or not it's like a a standard property though or if it's like a custom one.
Okay, let's let's do the next level.
Oops.
So, it's the Kansas Kansas H. What's the clear screen?
What's the clear screen um keyboard shortcut for PowerShell? Does anybody know?
CLS are clear.
Wars don't end. Which wars are we talking about?
IPV4. Okay, so we're dealing with some IP addresses now.
Okay, we've got our instructions and then we've got our solving method.
Okay. So, it's the next level, level two.
So, the password for cyborg 3 is the host A record. The host A record IP address for cyborg. What is this?
Plus the name of the file on the desktop.
All right.
host a record IP address. Host a record IP address.
So if we take a look at this file, oh, IPv4 is the name of the file on the desktop. So the thing we need to look up is host a record for this.
So I guess we're doing PowerShell lookup host information for domain.
Is it a domain we're looking up or is it What are we looking up again?
So we would call this like a UR like a URL.
So look up host information for URL.
To look up a host or DNS information for a URL in PowerShell, you first need to extract the host name from the URL and then pass it to resolve DNS name commandlet.
Okay, so resolve resolve DNS name.host We're looking for for this thing. Cyber something something.
Okay, that doesn't that doesn't work.
Oh, we're just looking for like the IP address.
Yeah. Okay. Okay. This makes it easier.
So, let's see. PowerShell lookup IP address for host name for Yeah, I think it should be host name, right? Look up IP address for host name.
Okay. So, resolve DNS name equals something something.
So, the name is going to be like cyber something something this thing.
Yeah, we found it. Okay, great.
So, resolve DNS name.
So, combine the IP address with this IPv4.
Okay. Al together the password is this thing underscore IPv4.
Okay, let's just double check that this is the correct password.
And it is the correct password. Awesome.
Okay. So, we'll do we'll do one more level.
Okay. Adb says 2011.
barely anyone had smartphones and now in 2026 we have AI. I mean technology kind of works like that.
I was in where I was in where was I in 2011?
I was in South Korea. I was in South Korea teaching English in 2011 and nobody had smartphones.
Nobody I mean I the only people who had smartphones back in 2011 were people who had a lot of money.
The thing is that is that the carriers didn't really support smartphones back then.
Really cool job. It was a pretty It was a pretty fun job. It was a pretty good job for a person just out of um just out of college.
Did you learn Korean? Yeah, I learned a a good amount of Korean. I was able to get by. Okay.
Uh I was I was a person who liked to integrate into whatever country that I was working in. There are some people who absolutely refused who absolutely refused to learn the language while while they were there because they figured they would never use it after they left the country, but I tried to I tried to integrate as best I could.
Okay, there's the password.
Those people miss the point of going to another country. I mean, to some people, it's just a job.
To some people, it's just it's just a way of making money and they see it as a very utilitarian thing.
What are my instructions?
don't understand how people I mean I understand their I understand their their way of thinking. It's just that I don't really agree with that.
Were you glad you picked Korea over Japan or somewhere else? I mean I did all of them. I did Korea and then Japan and then China.
I did like I did five years of overseas uh English teaching.
Hold on. What was that password?
I doubt you get to use it often. I mean, there's there there are like Korean people living in my neighborhood, but I don't get I don't get a lot of opportunities to just bust it out. Maybe sometimes at like restaurants or something.
Okay. Back in the day, the AI was a web browser. I mean, everything was like Google searching.
Okay. Where are my instructions?
The number of users in the cyborg group within Active Directory plus the name of the file in the desktop. Okay, so that we're getting we're really getting into Active Directory stuff here.
Okay, I've had a hard time getting a good job in America.
I mean people who did education in Asia, they were just kind of like delaying uh most most people were like delaying getting a job in their chosen field after graduating from college cuz you needed to have like a degree in order to qualify for the jobs teaching English overseas.
the number of users in the cyborg group.
Okay, so first we need to get the number of users in the cyborg group.
I mean we can probably search for it pretty easily. PowerShell count numbers in Active Directory group.
It's useful to ease drop on strangers who assume you can't understand them. I don't know about that.
What was the gaming scene like in China?
The gaming scene in China. I mean I I don't think I was part I was not part of the gaming scene while I was in China. I was uh I was kind of not in I was not in the scene. As far as the gaming scene in China now it's mostly it mostly revolves around mobile games as far as I know.
Okay. So PowerShell get 80 group member identity your group name and then count.
Oh, is that it? Seems pretty easy.
Okay, I can hear the difference between the f and the th sound.
I'm pretty sure they have time limits.
Yeah, I mean these days it's a lot more strict.
So the name of the group is called cyborg.
Okay, so we got 88 and I think we want to add 88 objects.
The hardware scene in China was is where it's at least in one province. Um I think that most of the hardware manufacturing is done in the Guangong province in China. Although I could be wrong.
That was the province where I was uh where I was working.
Okay, let's see if this password works.
Yep, it worked. Great.
Let's go ahead and record this.
The password is 88 objects.
Got this thing.
Igel, hello. Nice to see you here. Hope you're having a good day.
Let's go ahead and copy this.
Whoops, not that one.
Get AD group member identity.
Okay.
That was quick.
Now I can move on to the next level.
The password for Cyborg 5 is the Thank you very much, Igal 64, for following on Twitch. Thank you. The password for Cyborg 5 is the PowerShell module with the version number of 8989 plus the name of the file. Okay.
PowerShell module.
Look up PowerShell module by version number.
to look up a PowerShell module by its specific version number. Get module fully qualified name.
So get module list available fully qualified name and then what module version where object dover version equals something something. Well, let's give it a try.
Did I miss the priv? Yeah. Yeah. I mean the the priv was the third hour of today's stream. So, if you want to go back to hour number three, although I guess it would be kind of difficult uh because we had to we had like a break.
I hate MS terminology. Fully qualified name. Fully qualified name. Sure. Sure.
Okay.
aac accounts. So get module list available.
I mean, I'm pretty sure we just need to list the available modules.
It's going to be a big whack a big whack of stuff.
Oh, okay. Okay. And then we can look up the version number where object version where object version equals something something. So, we're looking for 8989.
Okay.
Atvou says, "Is 30 hours of programming studies a week feasible to do?" Uh, it depends on what else you have to do during the week.
If you're a full-time student, then three 30 hours of programming studies is possible possible considering that um like a full-time full-time studies is usually around 40 First wear object. Thank you. Thank you. Topam versus nightcore and seg. Hey, what is up? What is up?
Okay. So, wear object.
Oh, got to spell everything correctly, of course.
No typos allowed.
Bacon.
Get bacon. What happens when you just when you type in get bacon?
It's bacon.
Pretty cool.
They were able to pone with that name.
Tupam versus Nightcore. H I expected asy art of Kevin Bacon. Well, I mean, it's one or the other.
So, this is level four.
Oh, kind to brick rolls. Okay.
Thank you very much, I I Man02.
Thank you very much for the follow on Twitch. Thank you.
Okay. And we'll record the instructions and the method of solve.
Okay.
I remember those commercials begging strips for do dogs. Oh, there has to be like um TV commercials, dogs begging for bacon treats.
What was the name of that product?
Pyina begging strips. Okay. Is this Dogs don't know it's not bacon? Are you Is this the thing you're thinking of? Uh, April or something else.
Now, what was that password?
Yeah, that one. Awesome. Awesome.
There was a retriever that would say it's bacon.
Okay. And uh you know what? We might move on to something else after this.
Under the wire PowerShell. Yeah. Yeah.
We're doing a PowerShell like a PowerShell CTF exercise.
It's basically like over the wire bandit but for PowerShell stuff.
It's a bit It's a bit dry, but you know, for some reason, PowerShell stuff is never as interesting as like Linux stuff. It's just a personal preference.
10,000 hours of mastery in a skill. I never learned phonics. Okay, that's what the research says. Well, I mean, programming mastery.
What kind of uh what kind of programming language do you want to do, though? Do you want to do Python or do you want to do C or C++ or something else?
People usually specialize.
The password is what are they looking for again?
the name, right?
Do Zigg or Cobalt? Yeah, of course. Only machine language counts.
Nedmax says 10,000 10,000 hours is mastering is mastering one area of programming, not programming in general.
That would require a lifetime. Get help, get bacon.
Get help, get bacon.
eggs. Okay. So, bacon eggs. Bacon eggs cuz they say it's the module name.
The module name. So, the module name is bacon.
So, bacon eggs.
It didn't work for you. Really?
Let's try to log in.
Matrix 4. How good is the movie Matrix 4? I did not watch it.
Well, I mean, bacon eggs worked for me.
True story. I had trouble learning to read until I stopped doing the phonics.
You were Hm. The phonics got in the way, huh?
Okay. So, let's let's finish off. Let's go ahead and do some I really want to do some low low-level stuff, right?
Let's try doing all cyber training. Cyber.it.
Oh, you memorized whole words instead of sounding them out. Okay, makes sense.
All right, so let's do some of these low-level software challenges over at allcyber.it.
These are all in Italian, of course, so it it's an extra layer of difficulty.
But there are 25 challenges. Okay, so we did the supermarket one. Let's do this one called hidden variable hidden variable. So this I mean this is probably the worst getting into cyber security as a career or am I wasting my time? Um, while F90 comp, hello, nice to see you here.
Um, I wouldn't get into cyber security as a career unless you were unless cyber security was something you were generally interested in. I wouldn't get into cyber security if you just want to see it as like a vehicle to get rich or to make a bunch of money. Although it's possible to get a bunch of money while working in cyber security. If that's the reason why you're doing it, I'd say that is probably the wrong reason to do it.
But what what are your where are your interests? F90 comp.
Let's get out of here.
And what's up with this challenge?
They've got um they've got a file for us to examine. So just copy that.
It's called hidden variable.
Okay. We'll download the file. Ooh.
Yeah. Okay. Let's just download it by clicking on the link.
Then we'll move it on into this directory.
Okay, so now we're doing a software a software hacking challenge. We need to figure out what the flag is inside of this inside of this binary called hidden variable. So, I guess the first thing we want to do is we want to make the thing executable and then it will destroy our computer because we downloaded from a sketchy website.
If you want to get rich, go for finance and get a job on Wall Street.
H.
Okay, let's run some strings on this.
So, the first thing we want to do is we want to make sure that there's no suspicious I see something. Uh, that might be a flag in here.
Latua flag.
Whoops.
So, there's a hidden variable in here, maybe. Okay. Thanks for the insight. I mean, you might want to take a look at F90 Comp. You might want to take a look at this website here or this web page.
Go to medicine. That's easier money. H.
All right. So, it's been a while since I've did done any s sort of uh software hacking stuff. We'll try Rodari 2 default hidden variable and then we will analyze it.
And then we'll print the disassembly function at main.
So they're talking about like a hidden hidden variable.
So, they've got a flag. It's a bunch of Are these Unicode code points?
Kiwi, hello. Nice to see you here. All these people, not enough likes on the stream. If you're enjoying what you're watching right now, go ahead and click on the thumbs up on the stream. Thank you.
Okay, we got some arc B, some arc C hidden variable. So, I guess let's let's translate this page.
Translate page from Italian to English.
Okay. I can no longer find my variable.
Could you lend me a hand?
Hidden variable. So, we're using Redari 2.
Although, I suppose I'll stick to using Reddara 2 for a little while.
List binary variables.
Use the I information command. So, it's I what?
List all symbols, functions, and global variables. So is for the symbols H.
Well, we've got we've got a variable called flag apparently.
Is there hacking in the Star Wars films?
Um, I think some of the I think some of the droids do some do some hacking. I'm not too completely sure.
So, we got a flag over here.
Global object.
Jackson, America. Hello. Nice to see you here. Hope you're having a good time.
So, there's this thing called the flag.
And then what are these?
So it looks like it prints out the flag here.
one like five characters.
What are we doing today? Uh we were doing some PowerShell hacking CTF exercises, but uh we kind of did a lot of them. Um so we're doing some different stuff now. We're doing some reverse engineering.
But of course, we're dealing with a website that's in Italian, so we have to Google translate some stuff.
Okay, you should try cutter. I've I've thought about it. Um the the one big impediment is that I I've never found a good way to install Cutter. Let's translate.
Okay. The something flag. Your flag.
Your flag.
So, this prints out your flag.
Well, this is a message, right?
So, I just need to make sure that these are code points.
H.
So if we just run the thing.
So something. Can you get the original It looks corrupted. Where did I live the Where did I leave the original? So the original flag. Ah, okay. So I think I understand.
So it tries to print out the flag, but it just comes out as a garble.
And this is this is this message here.
So there might be like um there might be like a hidden function.
Okay. So, Jackson says, "I was trying to install Ubuntu Linux into my 13-year-old laptop.
I made an a micro SD card as an installer, but during the during the bootup, the laptop could not read the micro SD card."
H Okay, let's see if we can identify some of these functions.
So there's a main function.
Was there like a there was this object called flag that we found over here. Where was it?
Flag here. So, can we can we look up what is in this memory?
I forgot all of my radar commands.
So, it's like print print hexodimal at this address.
Oh, wow.
There's the flag.
But how do we how do we get only the printable characters?
There's got to be some Linux fu we can do to get to get this.
So print hexodimal. Maybe print asy.
So let's see we're to print asky at memory address.
Mhm. An exact copy of it with xxd. Then strip out the non-printing. Oh, maybe.
Yeah.
So, PS to print null terminated as strings. Okay. So, PS. So, we'll try PS H.
That's just an F.
Okay. Not great at reversing. I mean, this is why we're here. We're here to get We're here to get better at reversing, but you know, Sisos Master's recommendation isn't it isn't a bad idea.
So, we just grab this and then turn it into like a hex dump cuz this this is basically a hex dump, right?
Nano flag.dump.
Paste it in. Save it out. Then we'll use xxd reverse printable on flag.dump.
H.
That still looks pretty rough.
Yeah. There are too many um null bites in the way. There are single characters surrounded with the nullles. Yeah.
I mean, what if we Okay, so we can output this to maybe we can pipe this into strings.
No, we can't.
I think let's do some fancy Linux fu. So, um, what's it od delimiter space field?
I don't know. Seven.
Was it TR?
No, no, no.
to output only certain fields.
Oh, it's the print statement. Okay. So, o print. So, it's o print third and first and third columns of the file. So, o print.
Well, I mean, we're only looking for the last column in this case.
So print like 1 2 3 4 5 6 7 8 H 9 And okay, so here's our flag.
We now need to delete.
Delete the dots and then delete the new lines.
Yeah, there we go.
Okay, and that's one reverse engineering challenge done.
I really want to get better at doing reverse engineering.
Submit.
Yep. Okay, let's see the write up.
Thank you. Thank you, Ignifer.
So this is for all cyber software hacking Olympiad.
Oh, I've got one.
I've already done this challenge before.
Okay. Well, I don't think I solved the challenge when I when I did tried doing this the last time. So, how this was five months ago, so almost half a year.
Okay, let's let's go ahead and actually solve the challenge this time cuz this looks like half the work. Yeah, it's about half the work, but not a not the not everything.
Okay, what's actually going on is that there is an object called flag that is at that is stored at a specific memory address.
Okay. Flagrante FL flagrant Elbow, hello. Nice to see you here. What is up? We're just uh hanging out. We're trying to do some software hacking challenges over here.
Okay. So this is all redari 2 radari 2 um syntax.
So is gives us the the list of variables or like um objects.
So the memory address we've got for this one is this.
So what we can do is we can print out the hexodimal located at this location, the memory location.
So, it's just going to be px at this.
Okay. And this gives us our flag.
But it looks there's got to be like a more elegant way of doing this.
All right. So, let's go ahead and go on for another hour or so. I could spend a lot of time doing reverse engineering challenges.
Okay. Flag is at this memory address.
So the flag is here, but it's um but it's messy.
Save the output from the hex dump into a file. Then use your Linux fu.
Reverse engineering is cool. I mean, I agree. You can definitely reverse engineering is very very cool especially if you can do it at high levels. I cannot but uh I'm trying to get there and I'm trying to share my share what I learn with all of you all.
Okay, that is done.
So what was the other easy one? So private club. So software hacking Olympiad.
Private club.
What were the other?
Supermarket.
Supermarket. Private club. What was supermarket again? I didn't do a write up.
I want to be the customer of the supermarket.
the customer of the month of the supermarket. Can you help me out? Okay.
And why don't you give this a try yourself?
So, we got the the compiled binary and we also have the C source code for the supermarket app.
Here's the thing. If you didn't document it, it didn't happen. So, we need to make it happen.
Let's download these files. So the source C and the supermarket Okay. So, let's take a look at the source code.
Oh, okay. Okay. So, we need to find some way to to purchase the flag and then it'll give you the flag for the uh for the thing.
So run supermarket.
So current.
So we have 10 euro.
Kosa voya compl. Uh I don't know what that means. What does it mean? Google translate.
What do you want to buy?
So my suspicion here is that we can buy negative amounts. Yeah. Can we underflow the current amount? So we'll try buying the um pasti past alakma.
And we'll just try the quantity. We'll buy minus 10,000.
Gihato dispatch. Um, you tried. I'm sorry. Okay.
So, we'll try running it again. We'll try buying this ultra ultra or like again or more.
We buy four of the three one maybe other. So like continue uh yes buy this. How many do you want? like negative -2.
Okay. So, we were able to buy a negative amount.
So, I guess I'm guessing that it it waits for you to it does the comparison of whether or not you have enough money to to buy the thing.
So if we choose three quantity minus one segmentation fault. So if we try to buy the flag and buy negative one of it it uh it crashes the program.
How many you want minus 30?
Now we've got 100. So, how many how many do we need to buy of this three thing to afford this?
Some a million.
I'm getting closer. How about 30,000?
How about 300,000?
H. Do we have enough?
No, we're like we're like a few off.
So, let's try buying negative a million.
Okay, now we definitely have enough. So, we can just buy the flag.
But when we try to buy the flag, it uh crashes the program. Maybe it crashes the program because we don't have the the flag file in here. Anyways, let's move on to the actual uh online version of the app over at All Cyber.
So, we'll buy the first item. We'll buy 1 million and then we will buy the flag.
Yeah, negative amount is not an amount.
Okay.
Yeah, we got it. This time we're going to document it so that we actually so that we actually did it.
Okay. So this challenge is called supermarket.
Okay. Okay. So this challenge is here.
The concept we need to understand for this challenge is business logic flaws.
So business logic flaws and I guess there's the whole concept of buying negative amounts.
So, buying negative amounts, this leads to the infinite money glitch.
Okay, so the method is solved. So the source code for this app looks like this.
And let's grab that source code.
Okay.
So there is there are a distinct lack of checks to ensure that user input doesn't doesn't include negative numbers.
which enables users to buy a negative amount of items.
Okay. So, I guess what we need to do is we need to identify the part of the program that doesn't do the check.
So price times amount.
And how do we like result scanf amount?
There's no check here.
Okay. So, what does this mean?
Um, never never trust user input. Yeah, that makes sense.
The flag costs 1 million1 million euro.
Sell or buy?
Buy negative 1 million of any of the lower price items to get a balance of over 1 million euro.
And I guess that's it.
Okay, we can move on to the next challenge. So, the next challenge is private club.
Okay. Only those who have the badge can join my private club. Smiley face.
Okay. If you want to give this a shot yourself, here's the link or sorry, here's the uh the netcat command.
So, private club, I think this is like um JavaScript challenge.
Okay. So, what kind of file is this?
Oh, this is just the executable.
So, we're not given the source code.
Okay, I actually have some notes for this, so I should probably take a look.
Stack buffer overflow variable overwrite overwrite to win.
So after downloading and making the binary executable, we run the binary.
The binary takes in two inputs, then exits.
This is what the main function disassembly looks like. Rear 2. Okay.
We see that there is a branch of the main function that that opens up a shell for us.
But in order to access the branch of the program, the the program must have a certain variable set.
So before the test instruction, the bite in the var memory address is loaded into the EX register.
And if the contents of the var the contents of var is smaller than the size of EAX, then the rest of the register is filled up with zeros.
This payload should solve the challenge.
HTO says, "Is Windows source code just encrypted? How do they hide their code?"
I mean, there's I mean, I haven't really taken a look at Windows binaries.
I'm sure if you were to work hard enough, you would be able to reverse engineer it.
They probably take some measures to make sure that their stuff is hard to reverse engineer as well.
Okay, let's see.
Apparently, I didn't solve the challenge on the Ally website, but I've got this um this write up here that I did. How many how long ago did I do this write up?
So, I did this write up 5 months ago as well. So, this was in this was in February or something.
Apparently, this is not actually. Wait. Oh, okay. Okay. This gives us a shell.
So, just cap the flag.
Wow. Wow. Wow. Wow. They don't encrypt.
Okay.
Bad scanf. So scan like scan I think this is supposed to um illustrate that scan f is an insecure is an insecure function in C.
Let's submit that flag.
Okay, that is the correct flag.
Great.
All right. And I guess we can move on to the next challenge, which is Instagram generator. Instagram, huh?
Let's get out of here.
Not insta, but enter. H.
So, what's going on with this challenge?
I found this service that generates phrases for Instagram.
At some point, however, he printed me sentences that he shouldn't have shown me. I think I think this is supposed to be some sort of um format vulnerability.
Okay, let's let's download these files first.
Out of bounds read maybe.
Let's move the source code files.
Okay. So, if we just run the thing, it crashes.
If we just run the program, it crashes.
All right.
Mhm. Okay, we got some phrases over here.
All right, let's try accessing the challenge with Netcat.
So, let's see. Input the number from 1 to 10 to get a phrase. To get your phrase, choose a number from 1 to 10 to get your phrase.
So maybe zero 11 12.
What if it's a really big number?
Hm.
What is this message?
Come back for new catchphrases. Okay, sure.
Although I guess We might want to um dump out memory addresses and we can do it like this like pointers.
Dump out the pointers.
Hm.
Otherwise, we'd have to figure out where the vulnerability is specifically.
So usually we need to identify where the the vulnerable function is.
There are a bunch of like common vulnerable functions uh in these beginner level binary exploitation challenges.
So maybe it's puts puts or scanf.
It's probably scanf because scanf is a like a notorious insecure function.
This gets saved to choice result is not one and or choice is greater than one. So it has to be over one. So it can't be negative system strings.
Wait, where do they define that? Okay, so system strings are characters.
If this is a beginner stream, then non- beginners would be so hard. Yeah. No, I mean, this isn't this isn't a beginner level stream necessarily. This the beginner level stuff was all at the beginning of the stream.
I'm really missing the color highlights.
Yeah. I mean, if if we wanted to see the color highlights, we would do this.
So, system strings, it uses these phrases here.
So, it's an array of characters.
One, two, three, four, five, 6, 7, 8, 9, 10.
Well, get character is not H.
So the system strings is also an array that the program uses to output to output the program um the program messages.
So they define flag in read mode. Oh, you know what? That's why the program must have crashed.
System strings 2.
So scan f scan off the contents of the flag and save it to system strings two.
So system strings two is I mean it starts starting it starts counting from zero. 0 1 2 3 4 5.
0 1 2 3 4 5 which means that um the flag is blank.
Yeah, I mean the flag is probably blank in the source code, but if we So how do we output the system system string too?
because we only have um control over the phrases that we get here.
Okay, let's try running the the netcat command. Where is it?
Okay, try 14. 14. Oh, that's kind of clever. Yeah, let's give it a shot.
It gave us something.
We need to go beyond the boundaries of the array. Sounds about right.
So 13 14 gives us something. 15 16 17 18 19 20 21 20 Ooh, we got timed out.
Okay, we need to locate the system strings array.
So the system strings array was like six big. I think we can jump with increments of five.
It's like 10.
So we start with 15 then 20 then 25 30 35 Oh wait I think there might be there might be an easier way of doing this. We could probably like debug.
We could debug using um using radar.
First, we need to make a make something called flag. Right.
Yeah. Flag. So, we'll make something called flag. Echo hacker frogs.
like and subscribe to a file called flag.
And then we can we might be able to supply like a like a memory address cuz scan sometimes scanf can take in some really weird looking stuff.
Anyways, so Redari 2 debug integram thing.
Whoops.
Okay. Analyze that.
And then PDF.
So where do they put this stuff?
We need to figure out where they store the the variables.
Relooks relocation is present. Addresses will not be fixed. Oh, that's that's um unfortunate.
Okay. So, I mean, we can find where they store this stuff, right?
Relative addresses might and offsets would.
So, we just need to figure out where where the string is. So, no pain mode gain.
The F open call. Yes. Open call.
the one that reads in the flag. Yeah.
Okay.
So, let's see. Flo open. Okay. So, call colon fop here.
String flag.
So, this reads in the flag.
I think what we need to do is we need to figure out where the where the system strings are are located though.
Maybe actually let's set a little um break point. So, we'll set a break point for over here right after it loads in the flag.
And then maybe we can take a look at what's in the memory at that point.
Uh, I forget what the terminology is to get the variables.
Okay. Local variables and arguments. So, AF, yeah, AFV. Let's call variables and arguments. So, AFV.
So, we got a bunch of different locations we could look at.
Yeah. Oh, there we go. There's our hacker frogs.
There's our hacker frogs message. Yeah.
So, I mean, we can't load this thing specifically, although it would be really nice if we could.
So, how far is it away from the other array?
Oh, that's a that's a good question.
So I'm pretty sure that this is so it's 012.
This is the memory address.
So this is the flag string.
The flag string array is here.
So the other one is the one with the phrases.
And I think it might be this.
No, that was the same one. Just a second.
Uh, Varten is here.
Ho ho. Hello. Nice to see you here. What is up?
So, this is a bunch of garbage.
We'll try this other one.
You're on try hackme now. That's great.
There we go.
This is where This is where the um the phrases are.
Whoops.
So something like this.
Okay. So how many what is the the difference between this one and this one? So it looks like how many bytes is this?
So 00 and FD uh FD let's hex to decimal 200.
Okay. Um, hey ho ho ho. Um, please stop typing in all caps. Thank you.
So, this is decimal number two 253. 253. Okay. So, let's let's give it a try from 253.
H.
So, it doesn't it doesn't let you do anything above a certain number. So, I wonder what that number is.
So, 100's fine. 200 is fine. 220 is still fine.
230 240 What was the number we were looking for?
253 252 253 crashes the program or it head.
So 255 immediately crashes the program.
240 also crashes the program. 230 230 to 27.
Hm.
259.
259.
So, what numbers are going to make the thing crash?
210 Parla Eng. Um, hello GX00. Nice to see you here. We're just doing some reverse engineering challenges.
But >> doesn't that compare to correspond to an integer length? Integer length.
Let's take a closer look at What's being referenced here?
Do we divide the address by the array size?
Yeah, I'm not too sure how we're supposed to be doing this.
So, print f system strings 3. There's nothing that specifically prints out system strings 2 though.
System strings 5.
System strings 2 is referenced up here.
Thank you very much. Reckless ties.
Thank you.
64 is the uh the string length.
String length.
So each one of these strings is supposed to be 64 bits in length or 64 characters in length.
It runs scan F on choice.
print f system strings three with the phrase at the index.
Mhm.
So a short index short index.
It's 13.
So 64. What is this? What is FS? FC scan F file scan.
Okay, let's let's get some hints cuz we can we're we're entitled to them. Yay.
I found this service that generates phrases for Instagram. At some point, however, he printed me sentences that he shouldn't have shown me.
Okay, so hints. Do you want to unlock the hint? Sure.
Check the management of the number you well enter. Well, where and how it moves it.
File scan formatted.
The number you enter, where and how it moves it.
Well, I mean, this is probably talking about we're probably doing some uh overflow, right?
Wait, if it's overflow, then maybe we can.
Do you have like some really big input.
I guess they don't really care about about like non-numerical input here either.
The rereamer is lagging, is it?
Oh, yeah. It's It's lagging pretty bad.
So if you give really big numbers, it just Ooh, wait. It didn't crash. I thought if we give it like really big numbers, it would just crash.
H probably a memory leak. I mean, it's it has to do with like buffering.
The longer the stream goes, it's um it gets further and further behind because of the the reream buffer on uh on YouTube.
Okay. So, since I've never deal dealt with some stuff like this before, I'm going to ask for I'm going to ask the AI for a little bit of help.
Okay. AI solve all my problems.
So this I guess we could call this um binary exploitation challenge.
So, we're supposed to access the what was it? System strings.
System strings to object.
What is the recommended method to arrive there? Bam.
I don't see a response. Okay, here we go.
Nice challenge. Here's a concise practical analysis on how you reach the system strings in this program. Keeping things readable and focused on what you can test locally. What the code does, it loads in a string from a file into system strings by doing fop scan f and then f close.
System strings is defined as six strings each 64 bytes with system strings being initially empty but it will be overwritten by the contents of the flag up to 63 characters stopping at whites space.
Okay. The only direct user input that could affect memory layout here is via scanf flows into choice index and end choice. The program uses scanf to read a number.
Scan F.
So let's see. Hu. Hu is unsigned, right?
But what is H?
A local array frazzy. Not um obviously overflowed here.
The key risk is that system strings is written from a file, not from user input. If you can influence the contents of the flag file, you can set system strings to any string.
the content of the flag file. H but given the challenge says access the system strings object to get the flag, you expected to leverage memory out memory layout or control flow to cause the program to print or otherwise reveal system strings after the initial load.
Okay, understand the print flow.
If we could manipulate the flag file, we would have won already. That's true.
Okay. After each iteration, it prints system strings and reads n choice. If n choice equals s, it loops again.
Otherwise, it ends by printing the system strings. If n choice equals s h.
Okay. File content as flag injection.
You can modify the flag file before running. I don't think we're doing that.
Format string printf misuse.
If system strings can be manipulated to include format specifiers, it could cause a format string vulnerability.
System strings is initializes as this and is overwritten only by scanf into system strings and writes the flag into the slot.
disabling certain protections. This this uh they really want us to to hack the hack the flag.
Okay. The intended route is likely a format string vulnerability via system strings being used as the format string to print f.
Mhm.
Experiment with flag content flag with a flag containing format specifiers. Um, we can't do that.
Yeah, the AI is not helping us out very much.
Can you link me the challenge? Yeah, I can certainly do that. It's over here.
We can also pick up the extra.
Maybe tell the AI that you suspect an offset entry.
Yeah. Okay. We can uh we can talk about that. Let's let's get the extra the the other hint.
Okay. Unsigned short choice equals zero.
Integer index equals zero.
H.
So the unsigned short is registered as your choice.
We suspect that we can access the system strings strings array from the from the choice variable.
by providing a number that is outside of the range of the frazzy of the frazzy array.
Okay, you can try manipulating the choice input to read memory beyond the fryzy array, but the code path doesn't expose system strings directly via that output. The realistic path is to leverage a format string vulnerability in the print f call using the string stored in system strings as a format content of system strings.
Okay, let's say let's tell this guy um straight up we cannot modify the contents of the flag file.
Okay. print f style format string vulnerabilities.
So we could try looking for stuff that looks like this.
We are getting stuff by going beyond.
So 12 13 14. So this is just like random random data.
What we need to find is we need to find where the actual system strings lie.
The other thing they they told us to pay a lot of attention to is uh this right over here. Right.
So hint to unsigned short choice equals zero. int index equals zero.
Can also give this hint to the AI.
We were told in a hint to pay attention to this part of the code.
Okay. If the code declares unsigned short choice and in index There are a couple of common pattern implications to investigate without modifying the flag file. So the unsigned short choice may be used to control which p code path is taken. Its value wraps at this value right here. So 65,536.
So if an input influences choice, you might trigger an outofbounds or misindex path even when the value seems small.
The integer index is assigned 32-bit value on most platforms.
I mean what happens if we give this big number here and this wraps around back to one.
That's interesting.
So if we So this should be number two.
Yeah.
Okay.
So that wraps around.
Okay. So What happens if we go beyond beyond this?
So this is the last one.
46 is the last one. What about 47 then?
It's just nothing. Okay.
Ah, okay. So, it just it just wraps around.
Just enter the number and it overflows.
Gives the flag. Enter that number and overflows.
I mean, if it over it overflows, yeah, but it doesn't it doesn't give us the flag necessarily.
I got the flag by literally entering 5533. Really?
65533.
Oh, okay. Okay. Okay. So, it I mean it wraps around But why? Okay. I I mean, we're we're pretty much um we're pretty much done.
Um I think I' what I'd like to do is I'd like to take a look at a write up to figure out why the program behaves like this.
I guess that was that was the next step.
The next step was to just step down. So from the big number just keep on going down in in value. So 536 535 534 cuz there are only so many values there.
All right. So let's talk about what we're going to be doing next week.
So, next week is week 30, and we've got some uh some new streams coming up. So, we're we're going to be doing a stream on Sunday that we're adding to our late night rotation. So, we're doing two late night streams, coding Sunday and co-working Tuesday to start off the week. And then we're going to do our regular streams on Wednesday and on Friday at our regular time.
But to people who like staying up late in North America, you're in for a treat cuz we're going to be doing leak code stuff on Sunday and then we're going to be learning C programming on Tuesday.
Thank you very much. Ho ho ho. Thank you. Thank you. Okay, so let's go ahead and All right. I'm going to copy what you uh what you provided there.
Nul sec. Thank you.
Okay.
And well, I mean, we're going to be uh going away for a little bit, but in the meantime, let's see who is doing infosex streaming. So, this is a fun list of people who do intros cyber security streams, hacking streams on YouTube and on Twitch. And usually if people are online, you'll see a green button over here. And I'm the only person.
That's okay. Let's see who's streaming on Twitch right now.
Looks like we've got Muhoodles. Okay, Muhoodles is usually doing some fun space stuff. Let's take a look at what she's doing.
Oh yeah. I mean, we we're usually doing beginner level stuff at the at the start of the stream. So, Muhoodles is doing some Ambassador Celebration stream, Astrobiology, and space news. Ask me anything. Okay, so she's definitely a very uh a very fun streamer. She does educational content. We're going to raid into her channel.
Raid Moo Hoodles.
Okay, when you arrive on our stream, if you could give this message right here, OS Frog Hip Hop Hack OS Frog, I'd really appreciate it. Thank you very much. And yeah, we'll see you on Sunday. Sunday is going to be the next stream. We're going to be doing some coding.
But have a great weekend. And uh until next time, HackerFrogs out in 5 4 3 2 1.
See you next time everybody.
Related Videos

TOP 15 Data compression Interview Questions and Answers 2019 Part-2 | Data compression | Wisdom jobs
wisdomjobs
281 views•2019-06-28

CTS 158: 802.11w Management Frame Protection
ClearToSend
4K views•2019-02-04

NDSS 2019 Send Hardest Problems My Way: Probabilistic Path Prioritization for Hybrid Fuzzing
NDSSSymposium
496 views•2019-04-02

How realistic is Cities: Skylines?
CityBeautiful
159K views•2019-02-14

GUIs & TUIs: Choosing a User Interface for Your Python Project | Real Python Podcast
realpython
2K views•2025-04-04

The OSI Model - Explained by Example
hnasr
225K views•2019-05-12

Cloud Computing - Introduction
elithecomputerguy
98K views•2019-10-07

From Traveler's Dilemma to Dynamic Routing | Demystifying Networking
IITBombayJuly
5K views•2019-08-04
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23