{"id":104,"date":"2017-10-01T15:00:09","date_gmt":"2017-10-01T15:00:09","guid":{"rendered":"http:\/\/www.pimedios.com\/wordpress\/?p=104"},"modified":"2020-08-30T19:42:47","modified_gmt":"2020-08-30T19:42:47","slug":"exploit-exercises-nebula-level00","status":"publish","type":"post","link":"https:\/\/www.pimedios.com\/wordpress\/blog\/2017\/10\/01\/exploit-exercises-nebula-level00\/","title":{"rendered":"Exploit Exercises &#8211; Nebula &#8211; level00"},"content":{"rendered":"<p>Quiero empezar esta serie de &#8220;guide throughs&#8221; con el primer nivel de la primera m\u00e1quina de <a href=\"https:\/\/exploit-exercises.com\/\">Exploit Exercises<\/a>: Nebula. Por si no lo conoc\u00e9is Exploit Exercises consiste en varios niveles en modo <em>Wargame <\/em>repartidos en varias m\u00e1quinas. A diferencia de otros, tienen un nivel did\u00e1ctico muy elevado y se presenta cada nivel con una dificultad incremental, tratando distintos temas.<\/p>\n<p>Aqu\u00ed vamos a presentar las soluciones tambi\u00e9n de forma incremental, puesto que lo mejor es que uno mismo resuelva enteramente cada nivel.<\/p>\n<p>Bueno, al grano. La descripci\u00f3n del nivel es:<\/p>\n<blockquote><p><em>This level requires you to <strong>find<\/strong> a Set User ID program that will run as the \u201cflag00\u201d account. You could also find this by carefully looking in top level directories in \/ for suspicious looking directories.<\/em><\/p>\n<p><em>Alternatively, look at the find man page.<\/em><\/p><\/blockquote>\n<p>B\u00e1sicamente buscar un ejecutable SUID que nos permita ejecutarlo como &#8216;flag00&#8217;. Nos dan como pista que busquemos directorios sospechosos en \/ o que usemos el comando <em>find.<\/em> Bueno, en este nivel no hay muchas m\u00e1s pistas que dar. Haz clic abajo para ver la soluci\u00f3n.<\/p>\n<!-- Content Reveal v2.3.3 -->\n<div class=\"scrhead\" onmouseover=\"document.body.style.cursor='pointer'\" onmouseout=\"document.body.style.cursor='default'\" onclick=\"acr_swap_display('ran_69e788306ca3a','0','','')\">\n<script type=\"text\/javascript\">document.writeln('<img src=\"https:\/\/www.pimedios.com\/wordpress\/wp-content\/plugins\/simple-content-reveal\/images\/image1.gif\" class=\"scrimg\" id=\"scrimg_ran_69e788306ca3a\" alt=\"Reveal content\" title=\"Reveal content\"\/>');<\/script> Haz clic para ver la soluci\u00f3n\n<\/div>\n<script type=\"text\/javascript\">document.writeln('<div style=\"display: none\" class=\"scrdiv\" id=\"scrdiv_ran_69e788306ca3a\">');<\/script>\n Vemos que find nos permite buscar recursivamente ficheros con unos permisos determinados usando el modificador <em>-perm<\/em> .<\/p>\n<p><a href=\"http:\/\/www.pimedios.com\/wordpress\/wp-content\/uploads\/2017\/10\/Screenshot-from-2017-10-01-165344.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-105\" src=\"http:\/\/www.pimedios.com\/wordpress\/wp-content\/uploads\/2017\/10\/Screenshot-from-2017-10-01-165344.png\" alt=\"\" width=\"722\" height=\"516\" srcset=\"https:\/\/www.pimedios.com\/wordpress\/wp-content\/uploads\/2017\/10\/Screenshot-from-2017-10-01-165344.png 722w, https:\/\/www.pimedios.com\/wordpress\/wp-content\/uploads\/2017\/10\/Screenshot-from-2017-10-01-165344-300x214.png 300w\" sizes=\"(max-width: 722px) 100vw, 722px\" \/><\/a><\/p>\n<p><strong>\/bin\/&#8230;\/flag00<\/strong> es bastante sospechoso, la verdad. Probamos a ejecutar y&#8230;<\/p>\n<p><a href=\"http:\/\/www.pimedios.com\/wordpress\/wp-content\/uploads\/2017\/10\/Screenshot-from-2017-10-01-165920.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-108\" src=\"http:\/\/www.pimedios.com\/wordpress\/wp-content\/uploads\/2017\/10\/Screenshot-from-2017-10-01-165920.png\" alt=\"\" width=\"722\" height=\"516\" srcset=\"https:\/\/www.pimedios.com\/wordpress\/wp-content\/uploads\/2017\/10\/Screenshot-from-2017-10-01-165920.png 722w, https:\/\/www.pimedios.com\/wordpress\/wp-content\/uploads\/2017\/10\/Screenshot-from-2017-10-01-165920-300x214.png 300w\" sizes=\"(max-width: 722px) 100vw, 722px\" \/><\/a><\/p>\n<p>Voil\u00e1!<\/p>\n<p><script type=\"text\/javascript\">document.writeln('<\/div>');<\/script>\n<!-- End of Content Reveal -->\n\n","protected":false},"excerpt":{"rendered":"<p>Quiero empezar esta serie de &#8220;guide throughs&#8221; con el primer nivel de la primera m\u00e1quina de Exploit Exercises: Nebula. Por si no lo conoc\u00e9is Exploit Exercises consiste en varios niveles en modo Wargame repartidos en varias m\u00e1quinas. A diferencia de otros, tienen un nivel did\u00e1ctico muy elevado y se presenta cada nivel con una dificultad &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.pimedios.com\/wordpress\/blog\/2017\/10\/01\/exploit-exercises-nebula-level00\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Exploit Exercises &#8211; Nebula &#8211; level00&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_mi_skip_tracking":false},"categories":[5],"tags":[],"_links":{"self":[{"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/posts\/104"}],"collection":[{"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/comments?post=104"}],"version-history":[{"count":4,"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/posts\/104\/revisions"}],"predecessor-version":[{"id":110,"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/posts\/104\/revisions\/110"}],"wp:attachment":[{"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/media?parent=104"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/categories?post=104"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pimedios.com\/wordpress\/wp-json\/wp\/v2\/tags?post=104"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}