{"id":2136,"date":"2016-07-05T18:32:12","date_gmt":"2016-07-05T16:32:12","guid":{"rendered":"https:\/\/www.asafety.fr\/?p=2136"},"modified":"2016-07-25T00:33:26","modified_gmt":"2016-07-24T22:33:26","slug":"wargame-ndh-2016-write-up-guessing-so-basic","status":"publish","type":"post","link":"https:\/\/www.asafety.fr\/en\/misc\/wargame-ndh-2016-write-up-guessing-so-basic\/","title":{"rendered":"[WARGAME NDH 2016] Write-Up \u2013 Guessing: So Basic"},"content":{"rendered":"<p><\/p>\n<p style=\"text-align: center;\"><strong>Write-up of the challenge \u201cGuessing\u00a0\u2013 So Basic\u201d of Nuit du\u00a0Hack 2016\u00a0Wargame<\/strong><\/p>\n<p>The weekend of 02-03 july 2016\u00a0is the WARGAME of the\u00a0<strong><a href=\"https:\/\/nuitduhack.com\/fr\/\" target=\"_blank\">Nuit du Hack 2016<\/a><\/strong>\u00a0as a <strong>Jeopardy CTF<\/strong>. Having had the opportunity and the time to participate with some colleagues and friends, here\u2019s a write-up resolution of the challenges which we could participate.<\/p>\n<ul>\n<li>Category:\u00a0<strong>Guessing<\/strong><\/li>\n<li>Name:\u00a0<strong>So Basic<\/strong><\/li>\n<li>Description :\u00a0<em>Mister Julien Ducul has a dog named Rex, his dog is 5 years old and so he wanna make a fancy website in order to mahe this birthday special. Unfortunately, he is not able to remember the credentials he has configured on the website.<\/em><\/li>\n<li>URL :\u00a0172.16.1.51<\/li>\n<li>Points : <b>50<\/b><\/li>\n<\/ul>\n<p style=\"text-align: center;\"><strong>tl;dr : Login : jducul &#8211; Password rex2011 (the dog is 5 years old)<\/strong><\/p>\n<p>For this challenge, a simple attempt to access &#8220;http:\/\/172.16.1.51&#8221; asked a login and password. According to the title of the challenge, we concluded that authentication is a &#8220;Basic Authentication&#8221;, generated via a simple &#8220;.htaccess&#8221; and &#8220;.htpasswd&#8221; for example.<\/p>\n<p>The category of the challenge, type &#8220;guessing&#8221; also informs that its resolution will go through various tests and judicious assumptions.<\/p>\n<p>Let&#8217;s analyze the statement:<\/p>\n<ul>\n<li>The creator of the protected website is called &#8220;Julien Ducul&#8221;. And the login is certainly first name, last name, or a combination of both.<\/li>\n<li>This gentleman has\u00a0a dog &#8220;Rex&#8221;. It is not uncommon that people put the name of their pet as a password.<\/li>\n<li>Other information of interest: the dog is 5 years old! Thus, he was born in 2011 :)!<\/li>\n<\/ul>\n<p>Just do some tests with logins \/ password potential &#8230;<\/p>\n<p>Series of logins:<\/p>\n<p>&nbsp;<\/p>\n<pre>julien\r\nJulien\r\nducul\r\nDucul\r\njulien.ducul\r\nJulien.Ducul\r\njducul<\/pre>\n<p>Series of passwords:<\/p>\n<pre>Rex\r\nrex\r\n2011Rex\r\n2011rex\r\nRex2011\r\nrex2011<\/pre>\n<p>And the right combinaison :<\/p>\n<ul>\n<li>Login : <strong>jducul<\/strong><\/li>\n<li>Password : <strong>rex2011<\/strong><\/li>\n<\/ul>\n<p>From there, a &#8220;flag.txt&#8221; file is available, containing the flag.<\/p>\n<div id=\"attachment_2138\" style=\"width: 310px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.asafety.fr\/wp-content\/uploads\/guessing_bais_cauthn.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-2138\" class=\"size-medium wp-image-2138\" src=\"https:\/\/www.asafety.fr\/wp-content\/uploads\/guessing_bais_cauthn-300x163.png\" alt=\"guessing basic authN\" width=\"300\" height=\"163\" srcset=\"https:\/\/www.asafety.fr\/wp-content\/uploads\/guessing_bais_cauthn-300x163.png 300w, https:\/\/www.asafety.fr\/wp-content\/uploads\/guessing_bais_cauthn-768x416.png 768w, https:\/\/www.asafety.fr\/wp-content\/uploads\/guessing_bais_cauthn.png 799w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-2138\" class=\"wp-caption-text\">guessing basic authN<\/p><\/div>\n<p>Flag :\u00a0<strong>ndh2k16_68a3fhosqahxdxc<\/strong><\/p>\n<p>Thank you to all the team of the NDH2K16 for this event and for the whole organization!<\/p>\n<p>Greeting to\u00a0<a href=\"http:\/\/www.information-security.fr\/\" target=\"_blank\">nj8<\/a>, <a href=\"http:\/\/0xbadcoded.com\/\" target=\"_blank\">St0rn<\/a>, <a href=\"http:\/\/www.georgestaupin.com\/\" target=\"_blank\">Emiya<\/a>, Mido, downgrade,\u00a0Ryuk@n and\u00a0rikelm, ?\u00a0\/\/ Gr3etZ<\/p>","protected":false},"excerpt":{"rendered":"<p>Write-up of the challenge \u201cGuessing\u00a0\u2013 So Basic\u201d of Nuit du\u00a0Hack 2016\u00a0Wargame The weekend of 02-03 july 2016\u00a0is the WARGAME of [&hellip;]<\/p>\n","protected":false},"author":1337,"featured_media":2112,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[524,1,523,526,527,525],"tags":[498,499,459],"class_list":["post-2136","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ctf","category-misc","category-events","category-ndh","category-ndh2k16","category-wargame","tag-basic-authn","tag-guessing","tag-write-up"],"_links":{"self":[{"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/posts\/2136","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/users\/1337"}],"replies":[{"embeddable":true,"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/comments?post=2136"}],"version-history":[{"count":5,"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/posts\/2136\/revisions"}],"predecessor-version":[{"id":2142,"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/posts\/2136\/revisions\/2142"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/media\/2112"}],"wp:attachment":[{"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/media?parent=2136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/categories?post=2136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.asafety.fr\/en\/wp-json\/wp\/v2\/tags?post=2136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}