create account

Nebula level02 solution by tychebe

View this thread on: hive.blogpeakd.comecency.com
· @tychebe ·
Nebula level02 solution
<div class="separator" style="clear: both; text-align: center;">
<a href="https://3.bp.blogspot.com/-WoC75fPg22A/V-ZecIoKk6I/AAAAAAAAAMg/3rnHDCNZAIEft__04bRFIQ1FYs_QgTR6wCLcB/s1600/Nebula_level02_1.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="https://3.bp.blogspot.com/-WoC75fPg22A/V-ZecIoKk6I/AAAAAAAAAMg/3rnHDCNZAIEft__04bRFIQ1FYs_QgTR6wCLcB/s1600/Nebula_level02_1.jpg" /></a></div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
□ Aim : Execute getflag command with flag02 account and check the message &nbsp;"You have successfully executed getflag on a target account"</div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
□ Vulnerability : Refer the previous post(Nebula level02 hint)</div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
□ Source code interpretation</div>
<div style="margin-left: 1em;">
<div style="text-align: justify;">
○ The asprint function stores the value of USER environment variable to the buffer variable</div>
<div style="text-align: justify;">
○ The system function executes the command "/bin/echo USER is cool"</div>
</div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
□ Solving strategy</div>
<div style="margin-left: 1em;">
<div style="text-align: justify;">
○ Utilizing the SetUID, use flag02's authority when the program is executed</div>
<div style="text-align: justify;">
○ Utilizing the environment variable, execute the getflag command</div>
</div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
<br /></div>
<div class="separator" style="clear: both; text-align: center;">
<a href="https://4.bp.blogspot.com/-LLwtQbJSHno/V-ZecLf9WUI/AAAAAAAAAMk/6dMDkCJdUMwyGlaZ8PsfV28qkZVUwoS-QCLcB/s1600/Nebula_level02_2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="https://4.bp.blogspot.com/-LLwtQbJSHno/V-ZecLf9WUI/AAAAAAAAAMk/6dMDkCJdUMwyGlaZ8PsfV28qkZVUwoS-QCLcB/s1600/Nebula_level02_2.jpg" /></a></div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
If you move to /home/flag02 and execute ./flag02, you can check the result like the upper image.</div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
Insert "dummy;getflag" value to USER environment variable. Due to the semicolon, It is separated into two sentences.</div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
<br /></div>
<div class="separator" style="clear: both; text-align: center;">
<a href="https://2.bp.blogspot.com/-fxYinyNDups/V-ZecOBVVpI/AAAAAAAAAMc/6uZnHFroKLkSUU6hPjxWnsXnPttwPSHmgCLcB/s1600/Nebula_level02_4.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="https://2.bp.blogspot.com/-fxYinyNDups/V-ZecOBVVpI/AAAAAAAAAMc/6uZnHFroKLkSUU6hPjxWnsXnPttwPSHmgCLcB/s1600/Nebula_level02_4.jpg" /></a></div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
Like the upper image, if you execute the flag02, the echo command prints the dummy string. Then the getflag command on the right of the semicolon is executed.</div>
<div style="text-align: justify;">
<br /></div>
<div style="text-align: justify;">
Clear</div>
👍  ,
properties (23)
authortychebe
permlinknebula-level02-solution
categorysecurity
json_metadata{"tags":["security","nebula","wargame"],"image":["https://3.bp.blogspot.com/-WoC75fPg22A/V-ZecIoKk6I/AAAAAAAAAMg/3rnHDCNZAIEft__04bRFIQ1FYs_QgTR6wCLcB/s1600/Nebula_level02_1.jpg","https://4.bp.blogspot.com/-LLwtQbJSHno/V-ZecLf9WUI/AAAAAAAAAMk/6dMDkCJdUMwyGlaZ8PsfV28qkZVUwoS-QCLcB/s1600/Nebula_level02_2.jpg","https://2.bp.blogspot.com/-fxYinyNDups/V-ZecOBVVpI/AAAAAAAAAMc/6uZnHFroKLkSUU6hPjxWnsXnPttwPSHmgCLcB/s1600/Nebula_level02_4.jpg"],"links":["https://3.bp.blogspot.com/-WoC75fPg22A/V-ZecIoKk6I/AAAAAAAAAMg/3rnHDCNZAIEft__04bRFIQ1FYs_QgTR6wCLcB/s1600/Nebula_level02_1.jpg","https://4.bp.blogspot.com/-LLwtQbJSHno/V-ZecLf9WUI/AAAAAAAAAMk/6dMDkCJdUMwyGlaZ8PsfV28qkZVUwoS-QCLcB/s1600/Nebula_level02_2.jpg","https://2.bp.blogspot.com/-fxYinyNDups/V-ZecOBVVpI/AAAAAAAAAMc/6uZnHFroKLkSUU6hPjxWnsXnPttwPSHmgCLcB/s1600/Nebula_level02_4.jpg"]}
created2016-09-24 11:14:03
last_update2016-09-24 11:14:03
depth0
children0
last_payout2016-10-25 11:20:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length3,455
author_reputation27,548,928,872
root_title"Nebula level02 solution"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id1,345,999
net_rshares251,886,084
author_curate_reward""
vote details (2)