<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Articles on Stephen Swanson</title>
    
    
    
    <link>https://stephenswanson.xyz/articles/</link>
    <description>Recent content in Articles on Stephen Swanson</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>stephen@stephenswanson.xyz (Stephen Swanson)</managingEditor>
    <webMaster>stephen@stephenswanson.xyz (Stephen Swanson)</webMaster>
    <copyright>Stephen Swanson - CC BY 3.0 US.</copyright>
    <lastBuildDate>Sun, 26 Jun 2022 13:37:00 -0700</lastBuildDate>
    
	<atom:link href="https://stephenswanson.xyz/articles/index.xml" rel="self" type="application/rss+xml" />
    
    
    <item>
      <title>Staying Safe Post *Roe*</title>
      <link>https://stephenswanson.xyz/articles/staying-safe-post-roe/</link>
      <pubDate>Sun, 26 Jun 2022 13:37:00 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/staying-safe-post-roe/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;As of June 24, 2022, the U.S Supreme Court has &lt;a href=&#34;https://www.npr.org/2022/06/24/1102305878/supreme-court-abortion-roe-v-wade-decision-overturn&#34;&gt;overturned &lt;em&gt;Roe v. Wade&lt;/em&gt;, and &lt;em&gt;Casey v. Planned Parenthood&lt;/em&gt;&lt;/a&gt;, which gave all American women and other birthing Americans the right to abortions. Suffice it to say, this is a terrible decision, and it&amp;rsquo;s a punch in the gut that it happened during my lifetime. It shows that the fundamental human rights that I thought were guaranteed, for myself, and for my friends and family, simply can&amp;rsquo;t be counted on. And so, I implore you, even if you don&amp;rsquo;t seem to be affected by this ruling, please please please, take steps now to protect your privacy, rights, and security. And this is doubly true for women, my LGBTQ+ friends, and all vulnerable minorities.&lt;/p&gt;
&lt;h2 id=&#34;general-advice&#34;&gt;General advice&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;EFF&amp;rsquo;s Surveillance Self Defense: &lt;a href=&#34;https://ssd.eff.org&#34;&gt;https://ssd.eff.org&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;use-the-tor-browser&#34;&gt;Use the Tor Browser&lt;/h3&gt;
&lt;p&gt;Tor helps ensure that your internet service provider cannot see the websites that you visit. They can only see that you&amp;rsquo;re using Tor. If you&amp;rsquo;re concerned that your internet service provider might assist your adversaries, then you should be using tor for all sensitive work, such as visiting the rest of the links in this article.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;To download tor for computers: &lt;a href=&#34;https://www.torproject.org/&#34;&gt;https://www.torproject.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Specific advice for people using smartphones: &lt;a href=&#34;https://tb-manual.torproject.org/mobile-tor/&#34;&gt;https://tb-manual.torproject.org/mobile-tor/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Help using tor: &lt;a href=&#34;https://support.torproject.org/&#34;&gt;https://support.torproject.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Follow these tor safety tips: &lt;a href=&#34;https://www.makeuseof.com/tag/tor-browser-safety-tips/&#34;&gt;https://www.makeuseof.com/tag/tor-browser-safety-tips/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;use-signal&#34;&gt;Use Signal&lt;/h3&gt;
&lt;p&gt;In the United States, law enforcement can read all of your text messages without a warrant. Use an end to end encrypted alternative like Signal.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Signal: &lt;a href=&#34;https://signal.org&#34;&gt;https://signal.org&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Using Signal - Android: &lt;a href=&#34;https://ssd.eff.org/en/module/how-use-signal-android&#34;&gt;https://ssd.eff.org/en/module/how-use-signal-android&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Using Signal - IOS: &lt;a href=&#34;https://ssd.eff.org/en/module/how-use-signal-ios&#34;&gt;https://ssd.eff.org/en/module/how-use-signal-ios&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Keep in mind, especially when you&amp;rsquo;re making phone calls, it&amp;rsquo;s still technically possible for information about your conversations to be dangerous. For example, from EFF&amp;rsquo;s guide on communication:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;They know you called a gynecologist, spoke for a half hour, and then called the local Planned Parenthood&amp;rsquo;s number later that day, but nobody knows what you spoke about.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;For further reading on keeping safe while communicating:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://ssd.eff.org/en/module/communicating-others&#34;&gt;https://ssd.eff.org/en/module/communicating-others&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;dont-use-google&#34;&gt;Don&amp;rsquo;t Use Google&lt;/h3&gt;
&lt;p&gt;Use an alternative search engine like DuckDuckGo that keeps less information about your searches than other options&lt;/p&gt;
&lt;h3 id=&#34;use-cash&#34;&gt;Use Cash&lt;/h3&gt;
&lt;p&gt;In the United States, law enforcement can access all transactions on your credit and debit card, with either a subpoena or a warrant. Sensitive purchases, or purchases in sensitive locations, should be done with cash, if possible.&lt;/p&gt;
&lt;h3 id=&#34;if-youre-likely-to-be-arrested-take-special-precautions&#34;&gt;If you&amp;rsquo;re likely to be arrested, take special precautions&lt;/h3&gt;
&lt;p&gt;In the United States, law enforcement can legally compel you to unlock your devices with biometrics (fingerprints, FaceID). If that&amp;rsquo;s a risk, disable biometric authentication and set strong passwords on your devices. Odds are good that passwords are protected by the Fifth Amendment.&lt;/p&gt;
&lt;p&gt;Also consider using disappearing messages on Signal, which can automatically clean up messages that you don&amp;rsquo;t want people to see in case your phone is seized.&lt;/p&gt;
&lt;h2 id=&#34;specific-advice&#34;&gt;Specific Advice&lt;/h2&gt;
&lt;h3 id=&#34;women-and-birthing-persons&#34;&gt;Women and Birthing Persons&lt;/h3&gt;
&lt;h4 id=&#34;period-apps&#34;&gt;Period apps&lt;/h4&gt;
&lt;p&gt;Double check the privacy policy of any health apps you use. Ensure that they don&amp;rsquo;t sell your data. If you live in a place where period data could be used against you, ensure that any data is &lt;strong&gt;not synced to the cloud&lt;/strong&gt;. In the United States, law enforcement does not need a warrant to access data stored in the cloud. The most secure option is to use paper.&lt;/p&gt;
&lt;p&gt;For more reading, this NPR article is good: &lt;a href=&#34;https://www.npr.org/2022/05/10/1097482967/roe-v-wade-supreme-court-abortion-period-apps&#34;&gt;How period tracking apps and data privacy fit into a post-Roe v. Wade climate &lt;/a&gt;&lt;/p&gt;
&lt;h3 id=&#34;abortions&#34;&gt;Abortions&lt;/h3&gt;
&lt;p&gt;Follow the Electronic Frontier Foundation&amp;rsquo;s &lt;a href=&#34;https://www.eff.org/deeplinks/2022/06/security-and-privacy-tips-people-seeking-abortion&#34;&gt;guide for security and privacy for those seeking an abortion&lt;/a&gt;. Also understand the risks of having a phone with you: &lt;a href=&#34;https://ssd.eff.org/en/playlist/privacy-breakdown-mobile-phones&#34;&gt;Privacy Breakdown of Mobile Phones&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Please act with caution and follow good security practices. See this article for more information: &lt;a href=&#34;https://www.fastcompany.com/90468030/how-an-online-search-for-abortion-pills-landed-this-woman-in-jail&#34;&gt;How an online search for abortion pills landed this woman in jail&lt;/a&gt;&lt;/p&gt;
&lt;h3 id=&#34;lgbtq-people&#34;&gt;LGBTQ+ People&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;EFF&amp;rsquo;s Surveillance Self Defense guide for LGBTQ+ youth: &lt;a href=&#34;https://ssd.eff.org/en/playlist/lgbtq-youth&#34;&gt;https://ssd.eff.org/en/playlist/lgbtq-youth&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Security Tips for LGBTQ+ Dating: &lt;a href=&#34;https://www.eff.org/deeplinks/2021/06/security-tips-online-lgbtq-dating&#34;&gt;https://www.eff.org/deeplinks/2021/06/security-tips-online-lgbtq-dating&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Resources for Pride Activism: &lt;a href=&#34;https://www.eff.org/deeplinks/2020/06/pride-resources-activism-digital-and-physical-spaces&#34;&gt;https://www.eff.org/deeplinks/2020/06/pride-resources-activism-digital-and-physical-spaces&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;activists&#34;&gt;Activists&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;EFF&amp;rsquo;s Surveillance Self Defense guide for activists and protestors: &lt;a href=&#34;https://ssd.eff.org/en/playlist/activist-or-protester&#34;&gt;https://ssd.eff.org/en/playlist/activist-or-protester&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Safely attending a protest: &lt;a href=&#34;https://ssd.eff.org/en/module/attending-protest&#34;&gt;https://ssd.eff.org/en/module/attending-protest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Privacy of mobile phones: &lt;a href=&#34;https://ssd.eff.org/en/playlist/privacy-breakdown-mobile-phones&#34;&gt;https://ssd.eff.org/en/playlist/privacy-breakdown-mobile-phones&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4 id=&#34;those-involved-with-abortion-access&#34;&gt;Those Involved with Abortion Access&lt;/h4&gt;
&lt;p&gt;EFF has a good guide: &lt;a href=&#34;https://www.eff.org/deeplinks/2022/05/digital-security-and-privacy-tips-those-involved-abortion-access&#34;&gt;Digital Safety Tips: for providers of abortion support&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&#34;non-tech-resources&#34;&gt;Non-tech resources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Plan C pills: &lt;a href=&#34;https://www.plancpills.org/&#34;&gt;https://www.plancpills.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;I need an abortion: &lt;a href=&#34;https://www.ineedana.com/&#34;&gt;https://www.ineedana.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Funding for abortions: &lt;a href=&#34;https://abortionfunds.org/&#34;&gt;https://abortionfunds.org/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ACLU Reproductive Freedom Page: &lt;a href=&#34;https://www.aclu.org/issues/reproductive-freedom&#34;&gt;https://www.aclu.org/issues/reproductive-freedom&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Planned Parenthood: &lt;a href=&#34;https://plannedparenthood.org&#34;&gt;https://plannedparenthood.org&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sexual health resources at the University of Oregon: &lt;a href=&#34;https://health.uoregon.edu/sexualhealth&#34;&gt;https://health.uoregon.edu/sexualhealth&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If there&amp;rsquo;s anything I missed, if there are any corrections that need to be made, or if there are additional resources, both technical or non-technical that I should add, please, let me know. I only have one perspective on these issues, so any input would be greatly appreciated.&lt;/p&gt;

        
        </description>
    </item>
    
    <item>
      <title>The Head Bone is Connected to The Bash Shell- Compressor: HTB Cyber Apocalypse 2022</title>
      <link>https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-compressor/</link>
      <pubDate>Mon, 23 May 2022 00:00:00 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-compressor/</guid>
      <description>
        
          &lt;img src=&#34;https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-compressor/65c2b241534b236fedea2a3e6347549e.png&#34;/&gt;
          
        
        
        &lt;blockquote&gt;
&lt;p&gt;Ramona&amp;rsquo;s obsession with modifications and the addition of artifacts to her body has slowed her down and made her fail and almost get killed in many missions. For this reason, she decided to hack a tiny robot under Golden Fang&amp;rsquo;s ownership called &amp;ldquo;Compressor&amp;rdquo;, which can reduce and increase the volume of any object to minimize/maximize it according to the needs of the mission. With this item, she will be able to carry any spare part she needs without adding extra weight to her back, making her fast. Can you help her take it and hack it?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This was the first of the misc challenges. I&amp;rsquo;m not sure if my solution was intended, but it was easy and it works, so why not?&lt;/p&gt;
&lt;h2 id=&#34;the-challenge&#34;&gt;The Challenge&lt;/h2&gt;
&lt;p&gt;We&amp;rsquo;re given an ip and address of a python server. We have a nice set of menus that seem to correspond to the directory structure on the server.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;e3bac0797081972bfaba432934c6aa88.png&#34; alt=&#34;e3bac0797081972bfaba432934c6aa88.png&#34;&gt;&lt;/p&gt;
&lt;h2 id=&#34;the-solution&#34;&gt;The solution&lt;/h2&gt;
&lt;p&gt;Seeing linux commands anywhere in a challenge screams command injection. We can confirm this by trying some special characters, like &amp;lsquo;&lt;code&gt;;&lt;/code&gt;&amp;rsquo;, which is a way to chain commands together. Let&amp;rsquo;s try injecting the &lt;code&gt;id&lt;/code&gt; command after the &lt;code&gt;cat&lt;/code&gt; command:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;bf7eb4bd8487699f77bd9f3f7100c3bc.png&#34; alt=&#34;bf7eb4bd8487699f77bd9f3f7100c3bc.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;We see that we have command execution! Now we just need to find the flag. After using &lt;code&gt;ls&lt;/code&gt; commands on the parent directories, we eventually figure out that the flag is two directories above the current:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;dbae2dedd62d545d64a4c50bf9d58870.png&#34; alt=&#34;dbae2dedd62d545d64a4c50bf9d58870.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Lastly, we just use the cat command to read the flag!&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;232e4c82168f91d8a34cc64ebfc4341f.png&#34; alt=&#34;232e4c82168f91d8a34cc64ebfc4341f.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Boom! We have the flag! Hopefully Ramona can put this compressor to good use!&lt;/p&gt;
&lt;p&gt;If this was interesting at all, helped you with one of your challenges, or if you have any questions or corrections, please drop me a line!&lt;/p&gt;

        
        </description>
    </item>
    
    <item>
      <title>This One Math Trick Makes Banking Easy; Wallet Operators Hate It! - Genesis Wallet: HTB Cyber Apocalypse 2022</title>
      <link>https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-genesis-wallet/</link>
      <pubDate>Mon, 23 May 2022 00:00:00 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-genesis-wallet/</guid>
      <description>
        
          &lt;img src=&#34;https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-genesis-wallet/cover.png&#34;/&gt;
          
        
        
        &lt;blockquote&gt;
&lt;p&gt;To weaken the Golden Fang army, we must cut off their funding of the Genesis coins. Ulysses managed to perform a phishing attack against one of the financial operators of the mercenary and retrieved the login credentials &amp;ldquo;icarus:FlyHighToTheSky&amp;rdquo; for the Genesis wallet. However, the account is protected with 2FA. Can you hack into this renowned intergalactic wallet and move their funds to your account?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Sometimes, you know there&amp;rsquo;s a vulnerability in a piece of software that&amp;rsquo;s been patched, and you want to find the vulnerability so you can use it on an unpatched system. This CTF gave me a good opportunity to practice that. There was an unitended solution to the original genesis challenge. The operators patched the problem, but in a brand new challenge, leaving a vulnerable version up. I decided to see if I could reverse engineer the change and find the problem.&lt;/p&gt;
&lt;h2 id=&#34;the-challenge&#34;&gt;The Challenge&lt;/h2&gt;
&lt;p&gt;When we first browse to the page, we&amp;rsquo;re presented with a login/sign in prompt:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;4e0fcb82ed27c553021a061ccbe5f403.png&#34; alt=&#34;4e0fcb82ed27c553021a061ccbe5f403.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;After logging in with our new credentials, we&amp;rsquo;re required to keep track of a totp code:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;8b8b3ad97eb00b9fef6a4a3a6b39c816.png&#34; alt=&#34;8b8b3ad97eb00b9fef6a4a3a6b39c816.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;After saving it, and logging in with our new credentials and one time passcode, we&amp;rsquo;re presented with the main page.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;590495d0eaa9a4dd6600f920b36ec320.png&#34; alt=&#34;590495d0eaa9a4dd6600f920b36ec320.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re able to change our two factor code on the settings page, log out, view incoming and outgoing transactions, but the most important part, at least for us, is being able to send transactions:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;f9d6dda1e61837b84b530b56be62b3f4.png&#34; alt=&#34;f9d6dda1e61837b84b530b56be62b3f4.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Based on this information, my guess at the solution was to send something malicious to the &amp;lsquo;icarus&amp;rsquo; user. In order to do that, we need two things: the icarus&#39; address, and some kind of payload.&lt;/p&gt;
&lt;h2 id=&#34;the-solution&#34;&gt;The solution&lt;/h2&gt;
&lt;p&gt;This is the unintended solution, which I got during the competition. A different post will show the intended solution to the patched challenge: Genesis Wallet Redemption.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;a60d8d65393890ab46b6af35bb6fb5e2.png&#34; alt=&#34;a60d8d65393890ab46b6af35bb6fb5e2.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;After grabbing the zip files of the two challenges and putting them into a folder, as shown above, we can extract both of them:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-shell&#34; data-lang=&#34;shell&#34;&gt;$ unzip web_genesis_wallet
Archive:  web_genesis_wallet.zip
   creating: web_genesis_wallet
   ...
   
$ unzip web_genesis_wallet_redemption.zip 
Archive:  web_genesis_wallet_redemption.zip
   creating: web_genesis_wallet_redemption/
   ...
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Now, we can use the command &lt;code&gt;diff -r&lt;/code&gt;  to compare these two websites, and see what was changed in the patched version:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;1b92d3bdb70f78bb0287240c93f48080.png&#34; alt=&#34;1b92d3bdb70f78bb0287240c93f48080.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s a little suspicious. It looks like in the patched version, they added a check to prevent someone transfering negative amounts. So theoretically, if we knew icarus&#39; address, we could send them negative money, and drain their account that way.&lt;/p&gt;
&lt;p&gt;Probably the best place to look for the user&amp;rsquo;s address is in the registration flow. First, we look at &lt;code&gt;routes/index.js&lt;/code&gt;, at the &lt;code&gt;/api/register&lt;/code&gt; endpoint:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-javascript&#34; data-lang=&#34;javascript&#34;&gt;&lt;span class=&#34;nx&#34;&gt;router&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;post&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;/api/register&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;kr&#34;&gt;async&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;req&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;res&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
	&lt;span class=&#34;kr&#34;&gt;const&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;username&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;password&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;}&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;req&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;body&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;;&lt;/span&gt;

	&lt;span class=&#34;k&#34;&gt;if&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;username&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;password&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
		&lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;db&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;getUser&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;username&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
			&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;then&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;user&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
				&lt;span class=&#34;k&#34;&gt;if&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;user&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;res&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;status&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;401&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;).&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;send&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;response&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;Account already exists!&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;));&lt;/span&gt;
				&lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;db&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;registerUser&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;username&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;password&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
					&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;then&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(()&lt;/span&gt;  &lt;span class=&#34;p&#34;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;res&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;send&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;response&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;Account registered successfully&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)))&lt;/span&gt;
			&lt;span class=&#34;p&#34;&gt;})&lt;/span&gt;
			&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;k&#34;&gt;catch&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(()&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;res&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;status&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;500&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;).&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;send&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;response&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;Internal server error!&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)));&lt;/span&gt;
	&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;
	&lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;res&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;status&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;401&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;).&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;send&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;();&lt;/span&gt;
&lt;span class=&#34;p&#34;&gt;});&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We see that it calls the &lt;code&gt;db.registerUser&lt;/code&gt; function, and so we follow the trail there:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-javascript&#34; data-lang=&#34;javascript&#34;&gt;&lt;span class=&#34;kr&#34;&gt;async&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;registerUser&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;user&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;pass&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
	&lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;new&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;Promise&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;kr&#34;&gt;async&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;resolve&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;reject&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
		&lt;span class=&#34;k&#34;&gt;try&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
			&lt;span class=&#34;kd&#34;&gt;let&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;address&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;crypto&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;createHash&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;md5&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;).&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;update&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;user&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;).&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;digest&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;hex&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;
			&lt;span class=&#34;kd&#34;&gt;let&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;stmt&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;kr&#34;&gt;await&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;this&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;db&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;prepare&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;INSERT INTO users (username, password, address) VALUES ( ?, ?, ?)&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;
			&lt;span class=&#34;nx&#34;&gt;resolve&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;kr&#34;&gt;await&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;stmt&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;run&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;user&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;pass&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nx&#34;&gt;address&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;));&lt;/span&gt;
		&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;catch&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;e&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
			&lt;span class=&#34;nx&#34;&gt;reject&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nx&#34;&gt;e&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;);&lt;/span&gt;
		&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;
	&lt;span class=&#34;p&#34;&gt;});&lt;/span&gt;
&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;From this, we see that the user&amp;rsquo;s address is nothing more than the md5 hash of their username! We can generate icarus&#39; address using this command:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-shell&#34; data-lang=&#34;shell&#34;&gt;$ &lt;span class=&#34;nb&#34;&gt;echo&lt;/span&gt; -n &lt;span class=&#34;s2&#34;&gt;&amp;#34;icarus&amp;#34;&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;|&lt;/span&gt; md5sum
1ea8b3ac0640e44c27b3cb8a258a87f8  -
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The -n is necessary to prevent echo from adding a &lt;code&gt;\n&lt;/code&gt; character to the end and spoiling the hash.&lt;/p&gt;
&lt;p&gt;With that wallet address and the vulnerability, we&amp;rsquo;re ready to execute the attack. We go to the Genesis Wallet dashboard, and use the send button to send the address &lt;code&gt;1ea8b3ac0640e44c27b3cb8a258a87f8&lt;/code&gt; &lt;code&gt;-1337GTC&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;7b001f14242b5cceb8b91c0d09e4e941.png&#34; alt=&#34;7b001f14242b5cceb8b91c0d09e4e941.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;The last step is to go to the transactions page and verify the transaction:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;3b5d3a6e089cac22aee8dd0b86a6c439.png&#34; alt=&#34;3b5d3a6e089cac22aee8dd0b86a6c439.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;After the transaction is processed, we just have to go back to the dashboard, and enjoy our newfound wealth, as well as a shiny new flag:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;b1f321f6f176754a4b1276485c3a4a05.png&#34; alt=&#34;b1f321f6f176754a4b1276485c3a4a05.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;If this was interesting at all, helped you with one of your challenges, or if you have any questions or corrections, please drop me a line!&lt;/p&gt;

        
        </description>
    </item>
    
    <item>
      <title>Python PIL is Sus - Amidst Us: HTB Cyber Apocalypse 2022</title>
      <link>https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-amidst-us/</link>
      <pubDate>Wed, 18 May 2022 00:00:00 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-amidst-us/</guid>
      <description>
        
          &lt;img src=&#34;https://stephenswanson.xyz/articles/htb-cyber-apocalypse-2022-amidst-us/4443a8e2360636f3a99d97aec2a8a62a.png&#34;/&gt;
          
        
        
        &lt;blockquote&gt;
&lt;p&gt;The AmidstUs tribe is a notorious group of sleeper agents for hire. We have plausible reasons to believe they are working with Draeger, so we have to take action to uncover their identities. Ulysses and bonnie have infiltrated their HQ and came across this mysterious portal on one of the unlocked computers. Can you hack into it despite the low visibility and get them access?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This was a fun challenge, mainly because the correct path was fairly obvious, although exploitation required a little googling. It was great practice for python exploitation.&lt;/p&gt;
&lt;h2 id=&#34;the-challenge&#34;&gt;The Challenge&lt;/h2&gt;
&lt;p&gt;We&amp;rsquo;re given a web page with amonglings (?) on them, as well as a place to upload a file&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;9c92ee4755c77c68d5593a24abd09dab.png&#34; alt=&#34;9c92ee4755c77c68d5593a24abd09dab.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;We can upload an image, and the page returns the image with the alpha changed to a value that we can specify here:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;2abdcd8225379377f82919f427048239.png&#34; alt=&#34;2abdcd8225379377f82919f427048239.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re also given the complete source code, which shows that this is a python flask app.&lt;/p&gt;
&lt;h2 id=&#34;the-solution&#34;&gt;The Solution&lt;/h2&gt;
&lt;p&gt;From examining the page, we can see that we have one pathway through the code; via the &lt;code&gt;/api/alphafy&lt;/code&gt; endpoint. In a flask app, you can typically find all the routes in a file named &lt;code&gt;routes.py&lt;/code&gt; or something like that.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;nd&#34;&gt;@api&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;route&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;/alphafy&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;methods&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;POST&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;])&lt;/span&gt;
&lt;span class=&#34;k&#34;&gt;def&lt;/span&gt; &lt;span class=&#34;nf&#34;&gt;alphafy&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;():&lt;/span&gt;
	&lt;span class=&#34;k&#34;&gt;if&lt;/span&gt; &lt;span class=&#34;ow&#34;&gt;not&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;request&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;is_json&lt;/span&gt; &lt;span class=&#34;ow&#34;&gt;or&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;image&amp;#39;&lt;/span&gt; &lt;span class=&#34;ow&#34;&gt;not&lt;/span&gt; &lt;span class=&#34;ow&#34;&gt;in&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;request&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;json&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
		&lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;abort&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;400&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;

	&lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;make_alpha&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;request&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;json&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This route just calls calls a function called &lt;code&gt;make_alpha&lt;/code&gt; , which we can trace back to the &lt;code&gt;utils.py&lt;/code&gt; file.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;make_alpha&lt;/code&gt; function is too long to include in it&amp;rsquo;s entirety, but here are a few snippets that are relevant:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;k&#34;&gt;def&lt;/span&gt; &lt;span class=&#34;nf&#34;&gt;make_alpha&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;data&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;):&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;color&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;data&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;get&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;background&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;255&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;255&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;255&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;])&lt;/span&gt;

    &lt;span class=&#34;k&#34;&gt;try&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
        &lt;span class=&#34;n&#34;&gt;dec_img&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;base64&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;b64decode&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;data&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;get&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;image&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;encode&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;())&lt;/span&gt;

        &lt;span class=&#34;n&#34;&gt;image&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;Image&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;open&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;BytesIO&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dec_img&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;))&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;convert&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;RGBA&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
        &lt;span class=&#34;n&#34;&gt;img_bands&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;band&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;convert&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;F&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;for&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;band&lt;/span&gt; &lt;span class=&#34;ow&#34;&gt;in&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;image&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;split&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;()]&lt;/span&gt;

        &lt;span class=&#34;n&#34;&gt;alpha&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ImageMath&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;eval&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;
            &lt;span class=&#34;sa&#34;&gt;f&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;&amp;#34;&amp;#34;float(
&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;				max(
&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;				max(
&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;					max(
&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;					difference1(red_band, &lt;/span&gt;&lt;span class=&#34;si&#34;&gt;{&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;color&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;0&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt;&lt;span class=&#34;si&#34;&gt;}&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;),
&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;					&amp;#34;&amp;#34;&amp;#34;&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;# just for syntax highlighting&lt;/span&gt;
					&lt;span class=&#34;c1&#34;&gt;# ...&lt;/span&gt;
					&lt;span class=&#34;c1&#34;&gt;# ...&lt;/span&gt;
					&lt;span class=&#34;c1&#34;&gt;# ...&lt;/span&gt;
			        &lt;span class=&#34;n&#34;&gt;new_image&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;save&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;buffer&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;format&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;PNG&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;

        &lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
            &lt;span class=&#34;s2&#34;&gt;&amp;#34;image&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt; &lt;span class=&#34;sa&#34;&gt;f&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;data:image/png;base64,&lt;/span&gt;&lt;span class=&#34;si&#34;&gt;{&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;base64&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;b64encode&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;buffer&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;getvalue&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;())&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;decode&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;()&lt;/span&gt;&lt;span class=&#34;si&#34;&gt;}&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;&lt;/span&gt;
        &lt;span class=&#34;p&#34;&gt;},&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;200&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Examining this function, it looks like the call of &lt;code&gt;ImageMath.eval&lt;/code&gt;  might be interesting. When looking for vulnerabilites, just the word eval in any context is a huge red flag.&lt;/p&gt;
&lt;p&gt;After some Googling, we figure out that something like CVE-2022-22817 might be interesting. Since we have a preliminary thumbs up, we can reach into our standard python bag of tricks and pull out a payload like:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;nb&#34;&gt;__import__&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;os&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;system&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;cp /flag.txt /app/application/static&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Since it seems like the color parameters are evaluated, we can try exploiting the parameters using Burp.&lt;/p&gt;
&lt;p&gt;First, we&amp;rsquo;ll send the api request to the Burp repeater:
&lt;img src=&#34;1049bd722aa2bee6abedcf7ad885d7fc.png&#34; alt=&#34;1049bd722aa2bee6abedcf7ad885d7fc.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Then, we&amp;rsquo;ll scroll to the bottom of the request, add our payload, and send it off:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;5472e9a4d14e7389abcb6c631b70c484.png&#34; alt=&#34;5472e9a4d14e7389abcb6c631b70c484.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ll see that we get a 400 response, indicating some kind of server error, but let&amp;rsquo;s check and see if we actually copied the flag to the &lt;code&gt;/static&lt;/code&gt; directory:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;dff9c4da6160cd37fada5fb000bc1f98.png&#34; alt=&#34;dff9c4da6160cd37fada5fb000bc1f98.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Boom! We have a working PoC. Time to use it on the actual challenge server!&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;697a1366d985e9940b436e02043a4610.png&#34; alt=&#34;697a1366d985e9940b436e02043a4610.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;This time, I&amp;rsquo;m not using the repeater, just the interceptor.&lt;/p&gt;
&lt;p&gt;After adding the exploit, we&amp;rsquo;ll pass it to the challenge server, and check if our exploit worked.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;f570cb5ae23e062bf416c4b3051659ac.png&#34; alt=&#34;f570cb5ae23e062bf416c4b3051659ac.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;And we get the flag, solving the challenge and giving us access to the internal networks of the mysterious amonglings!&lt;/p&gt;
&lt;p&gt;If this was interesting at all, helped you with one of your challenges, or if you have any questions or corrections, please drop me a line!&lt;/p&gt;

        
        </description>
    </item>
    
    <item>
      <title>How To Cheat At Wordle</title>
      <link>https://stephenswanson.xyz/articles/how-to-cheat-at-wordle/</link>
      <pubDate>Thu, 24 Mar 2022 00:00:00 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/how-to-cheat-at-wordle/</guid>
      <description>
        
          &lt;img src=&#34;https://stephenswanson.xyz/articles/how-to-cheat-at-wordle/cover.webp&#34;/&gt;
          
        
        
        &lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;
&lt;p&gt;I know a fair few people who are playing the &lt;a href=&#34;https://www.nytimes.com/games/wordle/index.html&#34;&gt;New York Time&amp;rsquo;s Wordle&lt;/a&gt;. I&amp;rsquo;m not very good at word games, so I started poking around to see if I could find the answer in my own way, and write a browser extension to do it for me.&lt;/p&gt;


&lt;div class=&#34;notices warning&#34; &gt;&lt;p&gt;Following the guide contained herein is guaranteed to put strain on your friendships with real Wordle players. Only continue if you&amp;rsquo;re willing to brave the consequences.&lt;/p&gt;
&lt;/div&gt;
&lt;h3 id=&#34;the-manual-way&#34;&gt;The Manual Way&lt;/h3&gt;
&lt;p&gt;It turns out that unlike some other Wordle-inspired games, the NYT Wordle just keeps the solution in the browser&amp;rsquo;s local storage, so the process for cheating looks something like this:&lt;/p&gt;


&lt;div class=&#34;notices note&#34; &gt;&lt;p&gt;I&amp;rsquo;m using Firefox here. You may have to modify the steps here if you&amp;rsquo;re using a different browser.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;First, go into the Firefox tool bar and select &amp;ldquo;More Tools&amp;rdquo;:&lt;/p&gt;

  &lt;img src=&#34;open-more-tools.webp&#34;  alt=&#34;Opening more tools in Firefox&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;p&gt;Next, open the Firefox web developer tools:&lt;/p&gt;

  &lt;img src=&#34;open-dev-tools.webp&#34;  alt=&#34;Opening the Firefox web developer tools&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;p&gt;Then, click &amp;ldquo;Storage&amp;rdquo;, then click &amp;ldquo;Local Storage&amp;rdquo;, then click &amp;ldquo;&lt;a href=&#34;https://nytimes.com&#34;&gt;https://nytimes.com&lt;/a&gt;&amp;rdquo;.&lt;/p&gt;

  &lt;img src=&#34;browse-local-storage.webp&#34;  alt=&#34;Finding the New York Times local storage entry&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;p&gt;The solution will be in the long string on the right:&lt;/p&gt;

  &lt;img src=&#34;found-solution.webp&#34;  alt=&#34;Finding the solution to the Wordle&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;h3 id=&#34;the-fun-way&#34;&gt;The Fun Way&lt;/h3&gt;
&lt;p&gt;After figuring out the above, I decided to write a little browser extension to automatically pull the solution from local storage for me. The extension is called Robotle, and it&amp;rsquo;s on my &lt;a href=&#34;https://gitlab.com/ArchWizard101/robotle&#34;&gt;Gitlab&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Here&amp;rsquo;s Robotle in action:

  &lt;img src=&#34;robotle.webp&#34;  alt=&#34;Robotle solving the wordle&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;

&lt;/p&gt;
&lt;p&gt;Robotle currently only works on the NYT wordle, and only supports Firefox. Maybe someday if the mood strikes me, I&amp;rsquo;ll extend him and make a more universal Wordle cheating tool.&lt;/p&gt;

        
        </description>
    </item>
    
    <item>
      <title>Getting Started In Security</title>
      <link>https://stephenswanson.xyz/articles/getting-started-in-security/</link>
      <pubDate>Wed, 23 Mar 2022 12:00:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/getting-started-in-security/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;This page represents a list of almost every resource that I&amp;rsquo;ve found useful on my journey to doing cybersecurity. If you&amp;rsquo;re brand new and interested in learning, or if you&amp;rsquo;re an old-timer exploring someone else&amp;rsquo;s viewpoint, I hope you find something interesting here.&lt;/p&gt;
&lt;h2 id=&#34;wargames&#34;&gt;Wargames&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://tryhackme.com/&#34;&gt;Tryhackme&lt;/a&gt;: One of the best places for a complete novice to start. After learning the ropes using TryHackMe, move on to HackTheBox.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.hackthebox.com/&#34;&gt;HackTheBox&lt;/a&gt;: Super great place for playing boot2root machines. A variety of difficulties. I&amp;rsquo;d say that easy to medium HackTheBoxMachines are roughly equivalent to OSCP level machines.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.hackthissite.org/&#34;&gt;HackThisSite&lt;/a&gt;: An older wargame which mainly focuses on exploitation of older web applications, but still super fun.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://overthewire.org/wargames/&#34;&gt;OverTheWire&lt;/a&gt; A classic wargame that starts with the fundamentals of Linux, and takes you up to complicated exploitation exercises. This is my favorite place to recommend to beginners.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.picoctf.org/&#34;&gt;PicoCTF&lt;/a&gt;: I haven&amp;rsquo;t used this one too much, but for learning the basics of Jeopardy-style CTFs, this is a great start.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.vulnhub.com/&#34;&gt;VulnHub&lt;/a&gt;: Place to find vulnerable virtual machines to put in your lab and attack.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://exploit.education/&#34;&gt;Exploit Education&lt;/a&gt;: A collection of challenges to teach binary exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;training&#34;&gt;Training&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://portswigger.net/web-security&#34;&gt;PortSwigger Web Security Academy&lt;/a&gt;: Incredible free resource that covers almost everything you need to know about web application hacking. It&amp;rsquo;s the replacement for the Web Application Hacker&amp;rsquo;s Handbook.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;youtube-channels&#34;&gt;Youtube Channels&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w&#34;&gt;LiveOverflow&lt;/a&gt;: Great security creator. Goes above and beyond to explain the &amp;ldquo;why&amp;rdquo; of all his exploits. My favorite series from him are the &lt;a href=&#34;https://www.youtube.com/playlist?list=PLhixgUqwRTjzzBeFSHXrw9DnQtssdAwgG&#34;&gt;Pwnie Island Series&lt;/a&gt;, and the &lt;a href=&#34;https://www.youtube.com/watch?v=iyAyN3GFM7A&amp;amp;list=PLhixgUqwRTjxglIswKp9mpkfPNfHkzyeN&#34;&gt;Binary Exploitation Playlist&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/RanaKhalil101&#34;&gt;Rana Khalil&lt;/a&gt;: Amazing videos walking through the entire PortSwigger Web Academy.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/OffensiveSecurityTraining&#34;&gt;S1REN from OffensiveSecurity&lt;/a&gt;: Offensive Security posts walkthroughs of Offensive Security Proving Grounds boxes by S1REN. Although she mainly sticks to OSCP-level boxes, I really appreciate how she demonstrates proper note taking, and I&amp;rsquo;ve taken many tips from her style.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/c/ippsec&#34;&gt;IppSec&lt;/a&gt;: A classic cybersecurity youtuber that posts video walkthroughs of every HackTheBox machine.&lt;/li&gt;
&lt;/ul&gt;

        
        </description>
    </item>
    
    <item>
      <title>My Favorite Resources</title>
      <link>https://stephenswanson.xyz/articles/my-favorite-resources/</link>
      <pubDate>Wed, 23 Mar 2022 12:00:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/my-favorite-resources/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;On this page is a list of resources that I&amp;rsquo;ve stumbled upon that have been helpful for my workflow. I&amp;rsquo;m not going to list super common tools like Nmap or Metasploit, just the ones that were unknown to me and really useful.&lt;/p&gt;
&lt;h2 id=&#34;reference&#34;&gt;Reference&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://ippsec.rocks&#34;&gt;Ippsec.Rocks&lt;/a&gt;: A website that allows you to search through IppSec videos for techniques and tools.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://book.hacktricks.xyz/&#34;&gt;Hacktricks&lt;/a&gt;: A huge compilation of techniques for exploitation and privilege escalation.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://pentestmonkey.net/cheat-sheet/shells/reverse-shell-cheat-sheet&#34;&gt;pentestmonkey&amp;rsquo;s Reverse Shell Cheatsheet&lt;/a&gt;: A place to copy-paste reverse shells.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;tools&#34;&gt;Tools&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://gchq.github.io/CyberChef/&#34;&gt;Cyberchef&lt;/a&gt;: The best tool for dealing with formatting and encoding.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://github.com/sc0tfree/updog&#34;&gt;UpDog&lt;/a&gt;: A great tool for exfiltration from a compromised machine.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://joplinapp.org/&#34;&gt;Joplin&lt;/a&gt;: The note taking app that works for me. It&amp;rsquo;s similar to Evernote and Cherrytree, but FOSS. Uses markdown formatting, so it&amp;rsquo;s really convenient for copy-pasting into Hugo or a Pandoc converter.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://flameshot.org/&#34;&gt;Flameshot&lt;/a&gt;: One of the best Linux screenshot utilities. I used this app to take and annotate the screenshots for my OSCP.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://portswigger.net/daily-swig&#34;&gt;The Daily Swig&lt;/a&gt;: Security focused news from PortSwigger&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.schneier.com/&#34;&gt;Schneier on Security&lt;/a&gt;: Great place for security news and opinion&lt;/li&gt;
&lt;/ul&gt;

        
        </description>
    </item>
    
    <item>
      <title>My Recommended Reading and Watching</title>
      <link>https://stephenswanson.xyz/articles/recommended-reading/</link>
      <pubDate>Wed, 23 Mar 2022 12:00:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/recommended-reading/</guid>
      <description>
        
          
          
          
        
        
        &lt;p&gt;On this page is a list of things that I&amp;rsquo;ve read or watched that were either interesting or inspiring.&lt;/p&gt;
&lt;h2 id=&#34;essays&#34;&gt;Essays&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;http://www.catb.org/~esr/faqs/hacker-howto.html&#34;&gt;How To Become A Hacker - Eric Steven Raymond&lt;/a&gt;: An interesting piece of writing that has informed my ideology, although I don&amp;rsquo;t agree with some of it. Also, the original author would completely disagree with my usage of it, given that most of what I do is more inline with his definition of &amp;ldquo;cracker&amp;rdquo; rather than &amp;ldquo;hacker.&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://www.paulgraham.com/gba.html&#34;&gt;The Word &amp;ldquo;Hacker&amp;rdquo; - Paul Graham&lt;/a&gt;: An interesting musing on the spirit found in a hacker, and how it relates to the larger society.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://www.paulgraham.com/college.html&#34;&gt;Undergraduation - Paul Graham&lt;/a&gt;: A how-to guide about becoming a hacker while in college.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;fiction-books&#34;&gt;Fiction Books&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.powells.com/book/hobbit-the-lord-of-the-rings-box-set-9780547928180&#34;&gt;The Hobbit and The Lord of the Rings - J.R.R Tolkien&lt;/a&gt;: Classics that I grew up reading and keep coming back to again and again.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.powells.com/book/dune-9780441172719&#34;&gt;Dune - Frank Herbert&lt;/a&gt;: Just a masterpiece that was a big part of my childhood.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;non-fiction-books&#34;&gt;Non-Fiction Books&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.powells.com/book/permanent-record-9781250237231&#34;&gt;Permanent Record - Edward Snowden&lt;/a&gt;: This book was a really interesting insight into the motivations and ideals of a person that I&amp;rsquo;ve admired for a long time (to completely destroy my chances of working at the CIA or NSA now). It was an interesting look into how patriotism and idealism can be found in a hacker.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.mitnicksecurity.com/ghost-in-the-wires&#34;&gt;Ghost In The Wires - Kevin Mitnick&lt;/a&gt;: Not a super applicable or relevant book to security today, but it&amp;rsquo;s a fun read.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://books.google.com/books/about/Social_Engineering.html?id=8dctAAAAQBAJ&#34;&gt;Social Engineering: The Art of Human Hacking&lt;/a&gt;: Just an interesting and practical book about what makes humanity tick.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://plumvillage.org/books/creating-true-peace/&#34;&gt;Creating True Peace - Thich Nhat Hanh&lt;/a&gt;: Although I don&amp;rsquo;t 100% agree with the philosophy posited by Thich Nhat Hanh, I found this book both insightful and inspiring, and it definitely gave me a great appreciation for the work of the monk.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;non-technical-talks&#34;&gt;Non-Technical Talks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=G0WRV7gosRA&#34;&gt;Bruce Schneier - Information Security in the Public Interest - DEF CON 27 Conference&lt;/a&gt;: A great talk that redefined my goals as a computer scientist.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=4YYvBLAF4T8&#34;&gt;The Search for the Perfect Door - Deviant Ollam&lt;/a&gt;:  Deviant Ollam is a master of public speaking and entertaining stories, while also demonstrating the real security problems in the physical world.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=c02mH7F1xvU&amp;amp;list=PLjLd1hNA7YVzyhhqBQaW-tF45xnS6oHAP&amp;amp;index=4&#34;&gt;Katie Knowles, How to (Holiday) Hack It: Tips for Crushing CTFs &amp;amp; Pwning Pentests | KringleCon 2019&lt;/a&gt;: A video I rewatch every time I&amp;rsquo;m stuck on something. It goes through a really helpful and inspiring problem-solving methodology.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=D5Nwg84cV1E&amp;amp;list=PLjLd1hNA7YVzyhhqBQaW-tF45xnS6oHAP&amp;amp;index=14&#34;&gt;John Hammond, 5 Steps to Build and Lead a Team of Holly Jolly Hackers | KringleCon 2019&lt;/a&gt;: Just a good video about bringing people into the community as a leader of an organization.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;technical-talks&#34;&gt;Technical Talks&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=obJdpKDpFBA&amp;amp;list=PLjLd1hNA7YVzyhhqBQaW-tF45xnS6oHAP&amp;amp;index=7&#34;&gt;Ron Bowes, Reversing Crypto the Easy Way | KringleCon 2019&lt;/a&gt;: One of the best and most interesting introductions to reverse engineering crypto. It&amp;rsquo;s helped me understand that the weakest link in a crypto program often isn&amp;rsquo;t the crypto itself, but the implementation around it, and I&amp;rsquo;ve used that to great effect in several challenges.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=ermEx0UvcqY&amp;amp;list=PLjLd1hNA7YVx99qJF3OoPF-qunjqw-SoU&amp;amp;index=4&#34;&gt;Tom Liston, RFC-3514 Compliant Pentesting: Being Good While You&amp;rsquo;re Being Bad | KringleCon 2021&lt;/a&gt;: Really funny video that also teaches you how to use python to automatically alter outgoing packets on the fly.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=80LPl9P8j_E&amp;amp;list=PLjLd1hNA7YVx99qJF3OoPF-qunjqw-SoU&amp;amp;index=6&#34;&gt;Nancy Gariché, Disclosing Security Vulnerabilities to OS Projects.. Like a Boss! KringleCon 2021&lt;/a&gt;: Super useful video that outlines good practices for disclosing vulnerabilities in OS projects.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;youtube-videos&#34;&gt;Youtube Videos&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=HsNVKetbFDY&#34;&gt;Should We Abolish Copyright? - Tom Nicholas&lt;/a&gt;: An interesting discussion about the merits of copyright in the internet age.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.youtube.com/watch?v=C1vW9iSpLLk&#34;&gt;A Meat Eater&amp;rsquo;s Case For Veganism - CosmicSkeptic&lt;/a&gt;: Although I found this video after I went vegan, it&amp;rsquo;s still the best summary of the arguments that had been simmering in my head for years that eventually convinced me.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;poetry&#34;&gt;Poetry&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;http://www.catb.org/~esr/writings/unix-koans/script-kiddie.html&#34;&gt;Master Foo and the Script Kiddie&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.robertfrost.org/reluctance.jsp&#34;&gt;Reluctance - Robert Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.robertfrost.org/mending-wall.jsp&#34;&gt;Mending Wall - Robert Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.robertfrost.org/dust-of-snow.jsp&#34;&gt;Dust of Snow - Robert Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.poemhunter.com/poem/two-tramps-in-mud-time/&#34;&gt;Two Tramps in Mud Time - Robert Frost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;http://www.potw.org/archive/potw192.html&#34;&gt;Ozymandias - Horace Smith&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

        
        </description>
    </item>
    
    <item>
      <title>Cracking RSA: The Hard Way</title>
      <link>https://stephenswanson.xyz/articles/cracking-rsa-the-hard-way/</link>
      <pubDate>Sat, 01 Jan 2022 14:09:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/cracking-rsa-the-hard-way/</guid>
      <description>
        
          &lt;img src=&#34;https://stephenswanson.xyz/articles/cracking-rsa-the-hard-way/key.webp&#34;/&gt;
          
        
        
        &lt;style&gt;
math {
    text-align: center;
}
&lt;/style&gt;
&lt;p&gt;Ever since I finished my OSCP in November of 2021, I haven&amp;rsquo;t done much in the field of cybersecurity. Since I&amp;rsquo;m awfully rusty, I decided to start from the very basics and play around with the HTB beginner track. One of the more interesting challenges I finished has been the Weak RSA challenge, which involved generating a private key from a public key with a known factorization. RSA is incredibly common, in fact, the connection to this very website has been secured by RSA (check the certificate details), but I never really explored the underlying math.&lt;/p&gt;
&lt;h2 id=&#34;the-challenge&#34;&gt;The Challenge&lt;/h2&gt;
&lt;p&gt;The challenge consists of a zip archive containing two files, &lt;code&gt;key.pub&lt;/code&gt; and &lt;code&gt;flag.enc&lt;/code&gt;. &lt;code&gt;flag.enc&lt;/code&gt; is the flag encrypted using RSA, and key.pub is a RSA public key in PEM format.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;# key.pub
-----BEGIN PUBLIC KEY-----
MIIBHzANBgkqhkiG9w0BAQEFAAOCAQwAMIIBBwKBgQMwO3kPsUnaNAbUlaubn7ip
4pNEXjvUOxjvLwUhtybr6Ng4undLtSQPCPf7ygoUKh1KYeqXMpTmhKjRos3xioTy
23CZuOl3WIsLiRKSVYyqBc9d8rxjNMXuUIOiNO38ealcR4p44zfHI66INPuKmTG3
RQP/6p5hv1PYcWmErEeDewKBgGEXxgRIsTlFGrW2C2JXoSvakMCWD60eAH0W2PpD
qlqqOFD8JA5UFK0roQkOjhLWSVu8c6DLpWJQQlXHPqP702qIg/gx2o0bm4EzrCEJ
4gYo6Ax+U7q6TOWhQpiBHnC0ojE8kUoqMhfALpUaruTJ6zmj8IA1e1M6bMqVF8sr
lb/N
-----END PUBLIC KEY-----
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt;
&lt;p&gt;After finishing the challenge, I found several people who posted writeups. (See &lt;a href=&#34;https://simeononsecurity.ch/writeups/hackthebox-challenges-crypto-weak_rsa/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;https://technicalciso.com/htb-weak-rsa/&#34;&gt;here&lt;/a&gt;), but most of them focused on using a tool to automate the attack. Instead, I wanted to do it by hand. For completeness sake though, after extracting the files, this command will solve the challenge:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-fallback&#34; data-lang=&#34;fallback&#34;&gt;$ podman run -it --rm -v $PWD:/data docker.io/razaborg/rsactftool --uncipher /data/flag.enc --publickey /data/key.pub  
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;

&lt;div class=&#34;notices note&#34; &gt;&lt;p&gt;I&amp;rsquo;m using podman here, since it&amp;rsquo;s more secure by design than docker, but you can simply swap podman with docker and the command should work as is, since they&amp;rsquo;re drop-in replacements of each other.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;After running the command, the program spits out the flag:
&lt;img src=&#34;d253e27545384568853cd36d1ad2211e.png&#34; alt=&#34;5d8abcbebf5aa3b3ab8e85445b8a3463.png&#34;&gt;&lt;/p&gt;
&lt;h2 id=&#34;rsa-the-nitty-gritty&#34;&gt;RSA: The Nitty Gritty&lt;/h2&gt;
&lt;p&gt;I wanted to know how the tool got the answer though, so I started digging into how RSA works under the hood.&lt;/p&gt;
&lt;p&gt;RSA is an asymmetric encryption algorithm, meaning that there are two keys used, one for encryption, and one for decryption. The security of RSA depends on the idea that it&amp;rsquo;s hard to factor the product of two prime numbers, but it&amp;rsquo;s easy to multiply those numbers.&lt;/p&gt;
&lt;p&gt;A public RSA key has two parts, a modulus and a public exponent. typically noted as &lt;em&gt;n&lt;/em&gt; and &lt;em&gt;e&lt;/em&gt;, respectively. A private key only needs to contain a private exponent, &lt;em&gt;d&lt;/em&gt;. This formula, where &lt;em&gt;m&lt;/em&gt; is the plaintext message and &lt;em&gt;c&lt;/em&gt; is the encrypted message, is used for encryption:&lt;/p&gt;
&lt;p&gt;$$ c = m^e\text{ mod } n $$&lt;/p&gt;
&lt;p&gt;while:&lt;/p&gt;
&lt;p&gt;$$ m = c^d \text{ mod } n $$&lt;/p&gt;
&lt;p&gt;is used for decryption.&lt;/p&gt;
&lt;p&gt;As an example &lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; imagine we wanted to encrypt the message &amp;ldquo;The attack will come at dawn&amp;rdquo; First, we would pick two random prime numbers that are roughly the same size, for example, &lt;em&gt;p&lt;/em&gt; = 79 and &lt;em&gt;q&lt;/em&gt; = 97.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;n&lt;/em&gt;, our modulus, is&lt;/p&gt;
&lt;p&gt;$$n = np = 79\cdot97 = 7663$$&lt;/p&gt;
&lt;p&gt;Next, we pick a random public exponent. Typically, this number is prime, since we must ensure that the exponent is not a factor of&lt;/p&gt;
&lt;p&gt;$$(p -1)(q-1) = 7488$$&lt;/p&gt;
&lt;p&gt;and picking a prime number simplifies that calculation. For this example, we pick &lt;em&gt;e&lt;/em&gt; = 23.&lt;/p&gt;
&lt;p&gt;Lastly, we find &lt;em&gt;d&lt;/em&gt; using this equation:&lt;/p&gt;

&lt;link rel=&#34;stylesheet&#34; href=&#34;https://stephenswanson.xyz/katex/katex.min.css&#34; /&gt;
&lt;script src=&#34;https://stephenswanson.xyz/katex/katex.min.js&#34;&gt;&lt;/script&gt;
&lt;script defer src=&#34;https://stephenswanson.xyz/katex/auto-render.min.js&#34; onload=&#34;renderMathInElement(document.body);&#34;&gt;&lt;/script&gt;&lt;span&gt;
  &lt;div class=&#34;katex-display&#34;&gt;
    &lt;div class=&#34;katexoverwrite&#34;&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;script&gt;
  var divs = Array.from(document.getElementsByClassName(&#34;katexoverwrite&#34;))
  katex.render(&#34;\n\\begin{aligned}\nd \u0026= e^{-1}\\text{ mod } (p -1)(q-1) \\\\\nd \u0026= 23^{-1} mod (79 -1)(97-1) \\\\\nd \u0026= 2279\n\\end{aligned}\n&#34;, divs.pop(), {
    throwOnError: false
});
&lt;/script&gt;
&lt;/span&gt;
&lt;p&gt;Now, we have our public key: 23,7663, and our private key: 2279, 7663. We share the public key with the person sending the message. They then convert the message into a number using a tool like &lt;a href=&#34;https://gchq.github.io/CyberChef/#recipe=To_Decimal%28%27Space%27,false%29&amp;amp;input=VGhlIGF0dGFjayB3aWxsIGNvbWUgYXQgZGF3bg&#34; title=&#34;https://gchq.github.io/CyberChef/#recipe=To_Decimal(&#39;Space&#39;,false)&amp;amp;input=VGhlIGF0dGFjayB3aWxsIGNvbWUgYXQgZGF3bg&#34;&gt;CyberChef&lt;/a&gt;&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt;:&lt;/p&gt;
&lt;p&gt;$$\text{The attack will come at dawn} = 84 104&amp;hellip;97 119 110$$&lt;/p&gt;
&lt;p&gt;Since the message must be shorter than the modulus, we break it into 33 three digit chunks:
&lt;span&gt;
  &lt;div class=&#34;katex-display&#34;&gt;
    &lt;div class=&#34;katexoverwrite&#34;&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;script&gt;
  var divs = Array.from(document.getElementsByClassName(&#34;katexoverwrite&#34;))
  katex.render(&#34;\n\\begin{aligned}\nm_1 \u0026= 841 \\\\\nm_2 \u0026= 041 \\\\\n\u0026...\\\\\nm_{33} \u0026= 110 \\\\\n\\end{aligned}\n&#34;, divs.pop(), {
    throwOnError: false
});
&lt;/script&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Now, we raise each chunk to the power of &lt;em&gt;e&lt;/em&gt; modulus &lt;em&gt;n&lt;/em&gt;&lt;/p&gt;
&lt;span&gt;
  &lt;div class=&#34;katex-display&#34;&gt;
    &lt;div class=&#34;katexoverwrite&#34;&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;script&gt;
  var divs = Array.from(document.getElementsByClassName(&#34;katexoverwrite&#34;))
  katex.render(&#34;\n\\begin{aligned}\nc_1 \u0026= 841^ {23} \\text{ mod } 7663 = 579 \\\\\nc_2 \u0026= 041^ {23} \\text{ mod } 7663 = 4278\\\\\n\u0026...\\\\\nc_{33} \u0026= 110^ {23} \\text{ mod } 7663 = 2367\\\\\n\\end{aligned}\n&#34;, divs.pop(), {
    throwOnError: false
});
&lt;/script&gt;
&lt;/span&gt;


&lt;div class=&#34;notices note&#34; &gt;&lt;p&gt;Python handles this math really easily using the &lt;code&gt;pow()&lt;/code&gt; function. To perform the encryption, you can simply do &lt;code&gt;c1 = pow(841, 23, 7663)&lt;/code&gt;, where 841 is the number, 23 is the exponent, and 7663 is the modulus. For small numbers using the modulus operator &lt;code&gt;%&lt;/code&gt; would work, but for large numbers, using the extra argument to the pow function makes it much easier.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;This leaves us with our encrypted string &lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;! To decrypt, simply repeat the process, but use the private exponent &lt;em&gt;d&lt;/em&gt; instead of &lt;em&gt;e&lt;/em&gt;:&lt;/p&gt;
&lt;span&gt;
  &lt;div class=&#34;katex-display&#34;&gt;
    &lt;div class=&#34;katexoverwrite&#34;&gt;&lt;/div&gt;
  &lt;/div&gt;
  &lt;script&gt;
  var divs = Array.from(document.getElementsByClassName(&#34;katexoverwrite&#34;))
  katex.render(&#34;\n\\begin{aligned}\nm_1 \u0026= 579^ {2279} \\text{ mod } 7663  = 841 \\\\\nm_2 \u0026= 4278^ {2279} \\text{ mod } 7663 = 041 \\\\\n...\u0026\\\\\nm_{33} \u0026= 2367^ {2279} \\text{ mod } 7663 = 110\\\\\n\\end{aligned}\n&#34;, divs.pop(), {
    throwOnError: false
});
&lt;/script&gt;
&lt;/span&gt;
&lt;p&gt;With the successful decryption, we can now securely communicate over an insecure channel. As long as &lt;em&gt;d&lt;/em&gt; is kept secret, and we are unable to factor the modulus, &lt;em&gt;n&lt;/em&gt;, this message will stay secure.&lt;/p&gt;
&lt;h2 id=&#34;breaking-rsa-the-old-fashioned-way&#34;&gt;Breaking RSA, the old fashioned way&lt;/h2&gt;
&lt;p&gt;Now that we have an understanding of how RSA works, we can begin attacking this key. In order to decrypt the message, we need to find &lt;em&gt;d&lt;/em&gt;. The first step is to see the components of the key.  I used the Python library &lt;a href=&#34;https://www.pycryptodome.org&#34;&gt;PyCryptodome&lt;/a&gt;. To see the components, we just import the key and PyCryptodome will expose the variables:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;kn&#34;&gt;from&lt;/span&gt; &lt;span class=&#34;nn&#34;&gt;Crypto.PublicKey&lt;/span&gt; &lt;span class=&#34;kn&#34;&gt;import&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;RSA&lt;/span&gt;

&lt;span class=&#34;k&#34;&gt;with&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;open&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;key.pub&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;keyfile&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;RSA&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;import_key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;keyfile&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;read&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;())&lt;/span&gt;

&lt;span class=&#34;nb&#34;&gt;print&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;e:&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;e&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;span class=&#34;nb&#34;&gt;print&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;n:&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;n&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Running the program:
&lt;img src=&#34;e52bd1a344294029b819d78d32061386.png&#34; alt=&#34;786fb13a5e40b8d32cbf4ac5923fe85e.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Since we know the modulus, we can check a database to see if this particular number has known factors. For this, I&amp;rsquo;ll use &lt;a href=&#34;http://factordb.com&#34;&gt;factordb.com&lt;/a&gt;. After &lt;a href=&#34;http://factordb.com/index.php?query=573177824579630911668469272712547865443556654086190104722795509756891670023259031275433509121481030331598569379383505928315495462888788593695945321417676298471525243254143375622365552296949413920679290535717172319562064308937342567483690486592868352763021360051776130919666984258847567032959931761686072492923&#34;&gt;pasting&lt;/a&gt; the modulus into factordb, we see that the two factors of this number are known:
&lt;img src=&#34;22a22326280e43d0bb58c6f46d30669a.png&#34; alt=&#34;6041b48aeca8ce895c650e7f0d55c41f.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;We can copy those into our python code as &lt;em&gt;p&lt;/em&gt; and &lt;em&gt;q&lt;/em&gt; from the equations above. Now, we know &lt;em&gt;e&lt;/em&gt; (which is part of the public key), &lt;em&gt;p&lt;/em&gt;, and &lt;em&gt;q&lt;/em&gt;, so we can calculate &lt;em&gt;d&lt;/em&gt;, the secret key, using one of the above equations!&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;kn&#34;&gt;from&lt;/span&gt; &lt;span class=&#34;nn&#34;&gt;Crypto.PublicKey&lt;/span&gt; &lt;span class=&#34;kn&#34;&gt;import&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;RSA&lt;/span&gt;

&lt;span class=&#34;k&#34;&gt;with&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;open&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;key.pub&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;keyfile&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;RSA&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;import_key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;keyfile&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;read&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;())&lt;/span&gt;

&lt;span class=&#34;n&#34;&gt;p&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;20423438101489158688419303567277343858734758547418158024698288475832952556286241362315755217906372987360487170945062468605428809604025093949866146482515539&lt;/span&gt;
&lt;span class=&#34;n&#34;&gt;q&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;28064707897434668850640509471577294090270496538072109622258544167653888581330848582140666982973481448008792075646342219560082338772652988896389532152684857&lt;/span&gt;
&lt;span class=&#34;n&#34;&gt;e&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;e&lt;/span&gt;
&lt;span class=&#34;n&#34;&gt;n&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;n&lt;/span&gt;

&lt;span class=&#34;n&#34;&gt;d&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;pow&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;e&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,((&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;p&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;*&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;q&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)))&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;# e^-1 mod (p-1)(q-1)&lt;/span&gt;

&lt;span class=&#34;nb&#34;&gt;print&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;d:&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;d&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;img src=&#34;74426cc6e1c7486f84ffdd375e5e82e2.png&#34; alt=&#34;8d380997ca78106f63aa73f9bc5d21be.png&#34;&gt;&lt;/p&gt;
&lt;p&gt;Now that we have the secret key, we simply have to use our decryption formula! Since the message is much smaller than the key, we don&amp;rsquo;t have to worry about chunking.&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;kn&#34;&gt;from&lt;/span&gt; &lt;span class=&#34;nn&#34;&gt;Crypto.PublicKey&lt;/span&gt; &lt;span class=&#34;kn&#34;&gt;import&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;RSA&lt;/span&gt;

&lt;span class=&#34;k&#34;&gt;with&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;open&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;key.pub&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;keyfile&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;RSA&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;import_key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;keyfile&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;read&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;())&lt;/span&gt;

&lt;span class=&#34;n&#34;&gt;p&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;20423438101489158688419303567277343858734758547418158024698288475832952556286241362315755217906372987360487170945062468605428809604025093949866146482515539&lt;/span&gt;
&lt;span class=&#34;n&#34;&gt;q&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;28064707897434668850640509471577294090270496538072109622258544167653888581330848582140666982973481448008792075646342219560082338772652988896389532152684857&lt;/span&gt;
&lt;span class=&#34;n&#34;&gt;e&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;e&lt;/span&gt;
&lt;span class=&#34;n&#34;&gt;n&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;n&lt;/span&gt;

&lt;span class=&#34;n&#34;&gt;d&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;pow&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;e&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,((&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;p&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;*&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;q&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)))&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;# e^-1 mod (p-1)(q-1)&lt;/span&gt;

&lt;span class=&#34;c1&#34;&gt;# Thanks to https://stackoverflow.com/a/62986942 for the decryption code.&lt;/span&gt;
&lt;span class=&#34;k&#34;&gt;with&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;open&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;flag.enc&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;rb&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;flagfile&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;encflag&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;int&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;from_bytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;flagfile&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;read&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(),&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;big&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;pt_int&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;pow&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;encflag&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;n&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;# m^d mod n&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;plaintext&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;pt_int&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;to_bytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;128&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;big&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;lstrip&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;sa&#34;&gt;b&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;&lt;/span&gt;&lt;span class=&#34;se&#34;&gt;\x00&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;nb&#34;&gt;print&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;plaintext&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Finally, we decrypt the flag:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;6b0b072cee204180bc6073d414235940.png&#34; alt=&#34;d8de6c983f6d3ba8f61afc659fda911c.png&#34;&gt;&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;RSA is an incredible invention. It&amp;rsquo;s strong enough to be used to secure countless SSH or HTTPS connections, but underneath is a small bit of elegant math that college freshman can understand. It&amp;rsquo;s honestly amazing to me that the simple exponentiation that I was bored with in my college algebra class is used as the foundation of internet security.&lt;/p&gt;
&lt;p&gt;As always, if this was interesting or if you learned a trick or two. Please drop me a line. I always appreciate feedback!&lt;/p&gt;
&lt;section class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34; role=&#34;doc-endnote&#34;&gt;
&lt;p&gt;Thanks to &lt;a href=&#34;https://en.wikipedia.org/wiki/RSA_%28cryptosystem%29#Example&#34; title=&#34;https://en.wikipedia.org/wiki/RSA_(cryptosystem)#Example&#34;&gt;Wikipedia&lt;/a&gt; and Bruce Schneier&amp;rsquo;s book &amp;ldquo;&lt;a href=&#34;https://www.schneier.com/books/applied-cryptography/&#34;&gt;Applied Cryptography&lt;/a&gt;&amp;rdquo; for all of this information and these examples.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:2&#34; role=&#34;doc-endnote&#34;&gt;
&lt;p&gt;The number is shortened for readability. This is the full chunked number: 841 041 013 297 116 116 979 910 732 119 105 108 108 329 911 110 910 132 971 163 210 097 119 110&amp;#160;&lt;a href=&#34;#fnref:2&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:3&#34; role=&#34;doc-endnote&#34;&gt;
&lt;p&gt;Again, here&amp;rsquo;s the full encrypted number: 579 4278 4986 6386 1497 1497 1024 7201 1444 5022 885 432 432 2695 7351 2367 7201 4329 292 1236 3680 2037 5022 2367&amp;#160;&lt;a href=&#34;#fnref:3&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/section&gt;

        
        </description>
    </item>
    
    <item>
      <title>Breaking Santa&#39;s Encryption for Fun and Profit</title>
      <link>https://stephenswanson.xyz/articles/breaking-santas-encryption-for-fun-and-profit/</link>
      <pubDate>Wed, 29 Apr 2020 13:53:30 -0700</pubDate>
      <author>stephen@stephenswanson.xyz (Stephen Swanson)</author>
      <guid>https://stephenswanson.xyz/articles/breaking-santas-encryption-for-fun-and-profit/</guid>
      <description>
        
          &lt;img src=&#34;https://stephenswanson.xyz/articles/breaking-santas-encryption-for-fun-and-profit/recoverCleartextDocmentChallengeDescription.webp&#34;/&gt;
          
        
        
        &lt;p&gt;Recently, I&amp;rsquo;ve had more time on my hands, so I decided to take a walk down memory lane and rediscover my favorite challenge of the &lt;a href=&#34;https://holidayhackchallenge.com&#34;&gt;2019 SANS Holiday Hack Challenge&lt;/a&gt;, number 10: the Elfscrow Crypto challenge.&lt;/p&gt;
&lt;p&gt;In order to solve this challenge, I relied heavily on &lt;a href=&#34;https://www.youtube.com/watch?v=obJdpKDpFBA&#34;&gt;this talk&lt;/a&gt; by Ron Bowes, and most of this was based on his methods.
I highly recommend watching the video, especially if anything here is confusing.&lt;/p&gt;
&lt;p&gt;After downloading everything, we end up with three files:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;elfscrow.exe&lt;/em&gt;, obviously the encryption program.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;elfscrow.pdb&lt;/em&gt;, the debugging symbols.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;ElfUResearchLabsSuperSledOMaticQuickStartGuideV1.2.pdf.enc&lt;/em&gt;, this looks like an encrypted PDF based on the filename.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We&amp;rsquo;re dealing with a Windows binary, so I decided to reverse engineer this application in a virtual machine. I used &lt;a href=&#34;https://github.com/fireeye/flare-vm&#34;&gt;Flare VM&lt;/a&gt;, since it&amp;rsquo;s built for this, however, you could probably get away with wine or any other Windows system. A quick note about using Flare: although it&amp;rsquo;s recommended to detach the VM from the internet, this program needs to connect back to the North Pole API servers in order to run, so you&amp;rsquo;ll have to connect your VM to the network.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s open up our VM and just play with the program. This is one of the most important steps, at least for me; I just run the program with different options and different inputs, and just take note of the &amp;ldquo;huh&amp;rdquo; moments.
When I was playing around with the program, at least at the beginning, I used an &lt;a href=&#34;http://textfiles.com/holiday/12-bugs&#34;&gt;ASCII text file&lt;/a&gt;. I figured it&amp;rsquo;d be easier to understand the mechanism with a human readable file.&lt;/p&gt;
&lt;p&gt;I played around for a little bit, encrypted the same file a few times in quick succession, and ended up with output that looked something like this. I&amp;rsquo;ve taken the liberty of highlighting the parts of the output that were interesting:&lt;/p&gt;

  &lt;img src=&#34;huh.webp&#34;  alt=&#34;Similar seeds in encryption program&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;




&lt;div class=&#34;notices note&#34; &gt;&lt;p&gt;Quick note before moving on, you might notice an HTTP warning. I had to use &lt;em&gt;&amp;ndash;insecure&lt;/em&gt; to force HTTP, since, as of this writing, there&amp;rsquo;s a cert error that causes the program to fail.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;I&amp;rsquo;ve highlighted two things. First, a major red flag is that the seed only changed slightly, from 1588005546 to 1588005549. This indicates that the random seed is based on the time, and not some other random data. It even looks similar to a timestamp, which is quickly confirmed by decoding one of the seeds into a date:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;$ date -d @1588005546
Mon &lt;span class=&#34;m&#34;&gt;27&lt;/span&gt; Apr &lt;span class=&#34;m&#34;&gt;2020&lt;/span&gt; 09:39:06 AM PDT
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In fact, the seed for the encryption is nothing more than the current time!&lt;/p&gt;
&lt;p&gt;Secondly, the key and key length are interesting to us. Instead of creating their own encryption algorithm, developers often rely on libraries that securely implement other algorithms, like AES. This is much more secure, since there&amp;rsquo;s less room for error on the programmers end, however, if we can identify the algorithm, it can make it easier for us to defeat it, since we can take advantage of libraries too.&lt;/p&gt;
&lt;p&gt;One way we can identify the algorithm is by looking at the key length. AES typically uses keys of around 16-32 bytes, while Blowfish can use between 4-56 bytes&lt;sup&gt;&lt;a href=&#34;https://pycryptodome.readthedocs.io/en/latest/src/cipher/blowfish.html&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;, and DES uses 8 bytes.&lt;/p&gt;
&lt;p&gt;Looking at the picture, we can see that the key is 8 bytes long, so it could be Blowfish, DES, or some other algorithm. I&amp;rsquo;m investigating DES first, since it&amp;rsquo;s more common.&lt;/p&gt;
&lt;p&gt;In order to determine the algorithm, I&amp;rsquo;m using a website that can encrypt and decrypt DES, Blowfish, and AES. I like &lt;a href=&#34;http://des.online-domain-tools.com&#34;&gt;http://des.online-domain-tools.com&lt;/a&gt; because we can play with the options easily.
Eventually, we figure out that the algorithm is indeed DES in CBC mode:&lt;/p&gt;

  &lt;img src=&#34;des1.webp&#34;  alt=&#34;Mostly successful DES decryption&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;p&gt;Everything looks good, except for the first 8 bytes. Let&amp;rsquo;s change the initial vector to null bytes:&lt;/p&gt;

  &lt;img src=&#34;des2.webp&#34;  alt=&#34;Successful DES decryption&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;p&gt;I stumbled into a little rabbit hole here. I knew that DES is considered weak and is deprecated, so I tried to figure out if there was a simple attack against it. I found out, though, that it would still take days to crack, so it&amp;rsquo;d be unfeasible for a CTF challenge.&lt;/p&gt;
&lt;p&gt;Based on what we know so far, we can draw a diagram that represents the algorithm behind Santa&amp;rsquo;s encryption:&lt;/p&gt;

  &lt;img src=&#34;elfScrowAlgorithm.webp&#34;  alt=&#34;Diagram of the program&#34;  class=&#34;center&#34;  style=&#34;border-radius: 4px;&#34;  /&gt;


&lt;p&gt;Now we can finally make a plan for approaching the actual challenge.
I like breaking it down into small components that can stand on their own. I.e, that I can test before moving on, so that I minimize the amount of code I have to debug at once.&lt;/p&gt;
&lt;p&gt;Looking at the diagram, there are three things our decryption program has to do:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;It has to decrypt DES using a key.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;It has to generate that key using a timestamp.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;It has to brute force the timestamp, since we only know roughly when the file was encrypted (December 6, 2019, between 7pm and 9pm UTC)&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;In essence, we&amp;rsquo;re stepping backwards through the diagram, reversing each element as we come across it.&lt;/p&gt;
&lt;p&gt;We can finally start a python script to decrypt our file. I&amp;rsquo;m using &lt;a href=&#34;https://pycryptodome.readthedocs.io/en/latest/&#34;&gt;PyCryptodome&lt;/a&gt; for a DES implementation. We can pull in our known options to make a little function like this:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;kn&#34;&gt;from&lt;/span&gt; &lt;span class=&#34;nn&#34;&gt;Crypto.Cipher&lt;/span&gt; &lt;span class=&#34;kn&#34;&gt;import&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;DES&lt;/span&gt;

&lt;span class=&#34;k&#34;&gt;def&lt;/span&gt; &lt;span class=&#34;nf&#34;&gt;decrypt&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;filebytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;):&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;initialValue&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;bytes&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;fromhex&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;0000000000000000&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;santasCipher&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;DES&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;new&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;DES&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;MODE_CBC&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;iv&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;initialValue&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;

    &lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;santasCipher&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;decrypt&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;filebytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The reason why we we split it up into separate functions is that we can test it easily, so let&amp;rsquo;s do that:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;kn&#34;&gt;import&lt;/span&gt; &lt;span class=&#34;nn&#34;&gt;sys&lt;/span&gt;

&lt;span class=&#34;k&#34;&gt;with&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;open&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;12bugs1.enc&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;rb&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;encryptedfile&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;bytes&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;fromhex&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s1&#34;&gt;&amp;#39;04b3fd0a56885f80&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;sys&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;stdout&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;buffer&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;write&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;decrypt&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;encryptedfile&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;read&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;()))&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Here, we convert the key which we got from the testing of the Elfscrow binary to a byte object. Then we decrypt the file and write it to the screen.
When we run this, we get the plaintext of our file.&lt;/p&gt;


&lt;div class=&#34;notices note&#34; &gt;&lt;p&gt;Since we&amp;rsquo;re using python3, the only way to write raw bytes without decoding them or including the &lt;em&gt;\x&lt;/em&gt; prefix is to write directly to stdout. That&amp;rsquo;s why I&amp;rsquo;m using &lt;em&gt;sys.stdout.buffer.write()&lt;/em&gt; instead of &lt;em&gt;print()&lt;/em&gt;. Problems with encoding and decoding cost me a few hours when I was first solving this.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;That&amp;rsquo;s the easy part. Now we have to figure out how to get the hex key from the seed.
For that, we need to look at the disassembly.&lt;/p&gt;
&lt;p&gt;I like using &lt;a href=&#34;https://ghidra-sre.org/&#34;&gt;Ghidra&lt;/a&gt;, it comes preinstalled with Flare VM, but java has to be installed manually. In addition, since we&amp;rsquo;re working with a &lt;code&gt;.pdb&lt;/code&gt; file, we have to register the DIA SDK.&lt;/p&gt;
&lt;p&gt;After we have the Elfscrow binary open in Ghidra, we can start poking around for interesting functions. Since we have a plan that we&amp;rsquo;re following, we can safely ignore much of &lt;code&gt;main&lt;/code&gt;, and instead look for the functions that involve cryptography. I&amp;rsquo;m not great at reading assembly, so my reversing is partially based on the decompiler. After a little bit of investigation, I found:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;generate_key&lt;/code&gt;, which appears to take a reference to an array, and fills that array with a generated key.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;super_secure_srand&lt;/code&gt;, which looks to be a custom implementation of the srand function. It&amp;rsquo;s called with an integer to seed the random number generator.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;super_secure_random&lt;/code&gt;, just returns a semi-random integer and updates the seed.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We need to implement all three of these functions in our decoder script in order to solve the challenge. Let&amp;rsquo;s start with &lt;code&gt;super_secure_srand&lt;/code&gt; because it seems to be the foundation for the other two functions:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-c++&#34; data-lang=&#34;c++&#34;&gt; &lt;span class=&#34;n&#34;&gt;super_secure_srand&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;kt&#34;&gt;int&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;param_1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d9r&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;PUSH&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d91&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;ESP&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d93&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dword&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;+&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;param_1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;// Loading the first parameter from the function call
&lt;/span&gt;&lt;span class=&#34;c1&#34;&gt;&lt;/span&gt;    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d96&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;PUSH&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d97&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;PUSH&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;s_Seed_&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;_&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;%&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d_004042e8&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;// Formatting for fprintf
&lt;/span&gt;&lt;span class=&#34;c1&#34;&gt;&lt;/span&gt;            
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d9c&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;CALL&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;dword&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt;
            
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;da2&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;ADD&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0x40&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;da5&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;PUSH&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;                                          
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;da6&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;CALL&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;dword&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;-&amp;gt;&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;MSVCR90&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;DLL&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;::&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;fprintf&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt;
            
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dac&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;ADD&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;ESP&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0xc&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;daf&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;ECX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dword&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;+&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;param_1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;// Putting the first parameter into ECX
&lt;/span&gt;&lt;span class=&#34;c1&#34;&gt;&lt;/span&gt;    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;db2&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;dword&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;DAT_0040602c&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;ECX&lt;/span&gt; &lt;span class=&#34;c1&#34;&gt;// Moving the first parameter into the variable [DAT_0040602c]
&lt;/span&gt;&lt;span class=&#34;c1&#34;&gt;&lt;/span&gt;            
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;db8&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;POP&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;db9&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;RET&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dba&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;align&lt;/span&gt;  &lt;span class=&#34;n&#34;&gt;align&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;6&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
                 
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We can see that this function prints the new seed, and then sets it in a global variable. This is easily recreated in python with:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;0&lt;/span&gt;

&lt;span class=&#34;k&#34;&gt;def&lt;/span&gt; &lt;span class=&#34;nf&#34;&gt;super_secure_srand&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;):&lt;/span&gt;
    &lt;span class=&#34;c1&#34;&gt;#print(&amp;#34;Seed = &amp;#34; + newSeed)&lt;/span&gt;
    &lt;span class=&#34;k&#34;&gt;global&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Next, lets take a peak at &lt;code&gt;super_secure_random&lt;/code&gt;:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-c++&#34; data-lang=&#34;c++&#34;&gt; &lt;span class=&#34;n&#34;&gt;super_secure_random&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;kt&#34;&gt;void&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dc0&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;PUSH&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dc1&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;ESP&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dc3&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;DAT_0040602c&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt;
             
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dc8&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;IMUL&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0x343fd&lt;/span&gt;
             
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dce&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;ADD&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0x269ec3&lt;/span&gt;
             
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dd3&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;DAT_0040602c&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;
             
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dd8&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;DAT_0040602c&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt;
             
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;ddd&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;SAR&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0x10&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;de0&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;AND&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0x7fff&lt;/span&gt;
             
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;de5&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;POP&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;de6&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;RET&lt;/span&gt;
    &lt;span class=&#34;mo&#34;&gt;00401&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;de7&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;align&lt;/span&gt;  &lt;span class=&#34;n&#34;&gt;align&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;9&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This function is a little bit more complicated, but we can take each instruction piece by piece and understand it.&lt;/p&gt;
&lt;p&gt;First we make a local copy of the global seed in the EAX register. Then we multiply our local copy by 0x343fd and add 0x269ec3 to it. Next, we save our local seed as the global seed. Lastly, we shift our local copy to the right by 0x10 and perform an AND against 0x7fff. We then return our local copy.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s confusing to think about in assembler, but implemented in python, it looks like this:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;k&#34;&gt;def&lt;/span&gt; &lt;span class=&#34;nf&#34;&gt;super_secure_random&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;():&lt;/span&gt;
    &lt;span class=&#34;c1&#34;&gt;# Mutating the original seed&lt;/span&gt;
    &lt;span class=&#34;k&#34;&gt;global&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;*&lt;/span&gt; &lt;span class=&#34;mh&#34;&gt;0x343fd&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;+&lt;/span&gt; &lt;span class=&#34;mh&#34;&gt;0x269ec3&lt;/span&gt;
    &lt;span class=&#34;c1&#34;&gt;# Saving a changed seed&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt;

    &lt;span class=&#34;c1&#34;&gt;# Mixing it up a little more&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class=&#34;mh&#34;&gt;0x10&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;&amp;amp;&lt;/span&gt; &lt;span class=&#34;mh&#34;&gt;0x7fff&lt;/span&gt;
    &lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;newSeed&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The arithmetic can be greatly simplified, but it&amp;rsquo;s easiest for me to track the binary operations if it&amp;rsquo;s all broken up into as many steps as possible.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;generate_key&lt;/code&gt; is a little more complicated. The function graph looks like this:&lt;/p&gt;

  &lt;img src=&#34;generate_key.webp&#34;  alt=&#34;Function graph of the generate key function&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;p&gt;If we break it up into separate pieces, however, and take each piece individually, we can still figure out what it does.
In the first block, we can skip most of it until the call to &lt;code&gt;time&lt;/code&gt;, since that&amp;rsquo;s the first place we see a value we&amp;rsquo;re interested in. We then head into a small set of instructions that call &lt;code&gt;super_secure_srand&lt;/code&gt; with the time:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-c++&#34; data-lang=&#34;c++&#34;&gt;  &lt;span class=&#34;mf&#34;&gt;00401e0&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;e&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;CALL&lt;/span&gt;  &lt;span class=&#34;n&#34;&gt;time&lt;/span&gt;
  &lt;span class=&#34;mf&#34;&gt;00401e13&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;ADD&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;ESP&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0x4&lt;/span&gt;
  &lt;span class=&#34;mf&#34;&gt;00401e16&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;PUSH&lt;/span&gt;  &lt;span class=&#34;n&#34;&gt;EAX&lt;/span&gt;
  &lt;span class=&#34;mf&#34;&gt;00401e17&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;CALL&lt;/span&gt;  &lt;span class=&#34;n&#34;&gt;super_secure_srand&lt;/span&gt;
          
  &lt;span class=&#34;mf&#34;&gt;00401e1&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;c&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;ADD&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;ESP&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0x4&lt;/span&gt;
  &lt;span class=&#34;mf&#34;&gt;00401e1&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;f&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;dword&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;+&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;local_8&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0x0&lt;/span&gt;
          
  &lt;span class=&#34;mf&#34;&gt;00401e26&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;JMP&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;LAB_00401e31&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Then we initialize the variable &lt;code&gt;local_8&lt;/code&gt; to 0. If we look back at the flow graph, we seem to be in a &lt;code&gt;for&lt;/code&gt; loop. Although the picture doesn&amp;rsquo;t show it, every loop the value is compared to 0x8. In C++, it would look like this:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-c++&#34; data-lang=&#34;c++&#34;&gt;&lt;span class=&#34;k&#34;&gt;for&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;kt&#34;&gt;int&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;i&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;0&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;;&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;i&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;&amp;lt;&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;8&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;;&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;i&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;++&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;{&lt;/span&gt;
    &lt;span class=&#34;c1&#34;&gt;// loop interior
&lt;/span&gt;&lt;span class=&#34;c1&#34;&gt;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Now we can look at the interior of the loop:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-c++&#34; data-lang=&#34;c++&#34;&gt;  &lt;span class=&#34;mf&#34;&gt;00401e37&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;CALL&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;super_secure_random&lt;/span&gt;
          
  &lt;span class=&#34;mf&#34;&gt;00401e3&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;c&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;MOVZX&lt;/span&gt;  &lt;span class=&#34;n&#34;&gt;ECX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;AL&lt;/span&gt;
  &lt;span class=&#34;mf&#34;&gt;00401e3&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;f&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;AND&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;ECX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;mh&#34;&gt;0xff&lt;/span&gt;
          
  &lt;span class=&#34;mf&#34;&gt;00401e45&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EDX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dword&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;+&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;param_1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt;
  &lt;span class=&#34;mf&#34;&gt;00401e48&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;ADD&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;EDX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;dword&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;EBP&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;+&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;local_8&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt;
  &lt;span class=&#34;mf&#34;&gt;00401e4&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;b&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;MOV&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;byte&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;ptr&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;EDX&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;CL&lt;/span&gt;
  &lt;span class=&#34;mf&#34;&gt;00401e4&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;d&lt;/span&gt;   &lt;span class=&#34;n&#34;&gt;JMP&lt;/span&gt;    &lt;span class=&#34;n&#34;&gt;LAB_00401e28&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;We call &lt;code&gt;super_secure_random&lt;/code&gt;, but only take the last 8 bits, which we AND with 0xff. Once we have the new value, we make it the &lt;code&gt;i&lt;/code&gt;th element in an 8 character long list.&lt;/p&gt;

  &lt;img src=&#34;forEach.webp&#34;  alt=&#34;A graph demonstrating the function of the generate key algorithm&#34;  class=&#34;center&#34;  style=&#34;border-radius: 3px;&#34;  /&gt;


&lt;p&gt;Basically, we generate a byte for each element in our 8 byte key.&lt;/p&gt;
&lt;p&gt;All told, the key generation algorithm looks like this in python:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;k&#34;&gt;def&lt;/span&gt; &lt;span class=&#34;nf&#34;&gt;generate_key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;randomSeed&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;):&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;keystring&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;&amp;#34;&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;super_secure_srand&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;randomSeed&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;k&#34;&gt;for&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;i&lt;/span&gt; &lt;span class=&#34;ow&#34;&gt;in&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;range&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;8&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;):&lt;/span&gt;
        &lt;span class=&#34;n&#34;&gt;keyElement&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;super_secure_random&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;()&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;to_bytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;10&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;byteorder&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;little&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)[&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;0&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt;
        &lt;span class=&#34;n&#34;&gt;keyElement&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;keyElement&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;&amp;amp;&lt;/span&gt; &lt;span class=&#34;mh&#34;&gt;0xff&lt;/span&gt;
        &lt;span class=&#34;n&#34;&gt;keystring&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;keystring&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;+&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;format&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;keyElement&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;02x&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;keystring&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;If we wanted to be 100% true to the program, we&amp;rsquo;d set &lt;code&gt;randomSeed&lt;/code&gt; equal to the current timestamp, but since we&amp;rsquo;re attempting to decrypt it, we need to have control over the variable.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s test what we have so far.
If we put in the seed 1588005546, and everything works right, we should get the key of the first run, &lt;code&gt;04b3fd0a56885f80&lt;/code&gt;:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;nb&#34;&gt;print&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;generate_key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1588005546&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;))&lt;/span&gt;
&lt;span class=&#34;c1&#34;&gt;# output: 04b3fd0a56885f80&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;And sure enough, we get the right hex value! Now, given the time the program was run, we can decrypt any document.&lt;/p&gt;
&lt;p&gt;We just have one more step: bruteforce the seed used for our PDF.&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s a slight problem though, between 7 and 9pm, there are 7200 seconds, which means 7200 different binary blobs, and looking for our PDF is akin to looking for a needle in a haystack, unless there&amp;rsquo;s a way to tell them apart.&lt;/p&gt;
&lt;p&gt;Luckily, at the beginning of most files, there&amp;rsquo;s an identifier. These are the &lt;a href=&#34;https://en.wikipedia.org/wiki/Magic_number_%28programming%29#In_files&#34;&gt;&amp;ldquo;magic bytes&amp;rdquo;&lt;/a&gt; of a file, and it&amp;rsquo;s how the &lt;code&gt;file&lt;/code&gt; utility can tell a PDF from a JPG. The bytes we&amp;rsquo;re looking for are &lt;code&gt;25 50 44 46&lt;/code&gt;, or &lt;code&gt;%PDF&lt;/code&gt; when they&amp;rsquo;re decoded.&lt;/p&gt;
&lt;p&gt;What we need to do is attempt decryption with every timestamp in the range, and check the first 4 bytes for the PDF magic number. First, lets get the two timestamps we&amp;rsquo;re interested in:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;$ date -d &lt;span class=&#34;s2&#34;&gt;&amp;#34;2019-12-06 7:00 PM UTC&amp;#34;&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;+%s&amp;#34;&lt;/span&gt;
&lt;span class=&#34;m&#34;&gt;1575658800&lt;/span&gt;
$ date -d &lt;span class=&#34;s2&#34;&gt;&amp;#34;2019-12-06 9:00 PM UTC&amp;#34;&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;+%s&amp;#34;&lt;/span&gt;
&lt;span class=&#34;m&#34;&gt;1575666000&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Now we just need to loop over every number between them and attempt to decrypt our file.
Here&amp;rsquo;s the python code:&lt;/p&gt;
&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-python&#34; data-lang=&#34;python&#34;&gt;&lt;span class=&#34;k&#34;&gt;def&lt;/span&gt; &lt;span class=&#34;nf&#34;&gt;bruteforceFileSeed&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;filebytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;firstTimestamp&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;secondTimestamp&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;):&lt;/span&gt;
    &lt;span class=&#34;c1&#34;&gt;#Using tqdm to display a fancy progress bar as we loop through every time between our two timestamps&lt;/span&gt;
    &lt;span class=&#34;k&#34;&gt;for&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt; &lt;span class=&#34;ow&#34;&gt;in&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;tqdm&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;range&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;firstTimestamp&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;secondTimestamp&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)):&lt;/span&gt;
        &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;generate_key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
        &lt;span class=&#34;n&#34;&gt;decryptedFilebytes&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;decrypt&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;nb&#34;&gt;bytes&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;fromhex&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;),&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;filebytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;

        &lt;span class=&#34;c1&#34;&gt;#Checking for PDF magic number&lt;/span&gt;
        &lt;span class=&#34;k&#34;&gt;if&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;decryptedFilebytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;0&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;4&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;==&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;bytes&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;fromhex&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;25504446&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;):&lt;/span&gt;
            &lt;span class=&#34;nb&#34;&gt;print&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;Success with key:&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;key&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;s2&#34;&gt;&amp;#34;and seed&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;seed&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
            &lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;decryptedFilebytes&lt;/span&gt;

    &lt;span class=&#34;c1&#34;&gt;#If we haven&amp;#39;t found anything in the range, exit with an error&lt;/span&gt;
    &lt;span class=&#34;nb&#34;&gt;print&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;Failure!&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
    &lt;span class=&#34;k&#34;&gt;return&lt;/span&gt; &lt;span class=&#34;kc&#34;&gt;None&lt;/span&gt;

&lt;span class=&#34;k&#34;&gt;with&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;open&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;sys&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;argv&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;1&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;rb&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;encryptedfile&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
    &lt;span class=&#34;c1&#34;&gt;#Begin the process&lt;/span&gt;
    &lt;span class=&#34;n&#34;&gt;decryptedFilebytes&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;=&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;bruteforceFileSeed&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;encryptedfile&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;read&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(),&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;1575658800&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;,&lt;/span&gt; &lt;span class=&#34;mi&#34;&gt;1575666000&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;

    &lt;span class=&#34;c1&#34;&gt;#If we&amp;#39;ve succeeded, write our decrypted bytes to the second file&lt;/span&gt;
    &lt;span class=&#34;k&#34;&gt;if&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;decryptedFilebytes&lt;/span&gt; &lt;span class=&#34;o&#34;&gt;!=&lt;/span&gt; &lt;span class=&#34;kc&#34;&gt;None&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
        &lt;span class=&#34;k&#34;&gt;with&lt;/span&gt; &lt;span class=&#34;nb&#34;&gt;open&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;sys&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;argv&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;mi&#34;&gt;2&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;],&lt;/span&gt; &lt;span class=&#34;s1&#34;&gt;&amp;#39;wb&amp;#39;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt; &lt;span class=&#34;k&#34;&gt;as&lt;/span&gt; &lt;span class=&#34;n&#34;&gt;decryptedfile&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;:&lt;/span&gt;
            &lt;span class=&#34;n&#34;&gt;decryptedfile&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;.&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;write&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;(&lt;/span&gt;&lt;span class=&#34;n&#34;&gt;decryptedFilebytes&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once we have all of that in our script, we&amp;rsquo;re finally ready to attempt to decrypt our file:&lt;/p&gt;

  &lt;img src=&#34;success.webp&#34;  alt=&#34;Successful decryption!&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;p&gt;After about two minutes, our loop breaks with the success message. The file was encrypted with the key &lt;code&gt;b5ad6a321240fbec&lt;/code&gt; at 1575663650.
Even better than that, we have a decrypted file waiting for us!
Let&amp;rsquo;s open up &lt;em&gt;ElfUResearchLabsSuperSledOMaticQuickStartGuideV1.2.pdf&lt;/em&gt; and see if it worked:&lt;/p&gt;

  &lt;img src=&#34;elfu.webp&#34;  alt=&#34;Decrypted PDF&#34;  class=&#34;center&#34;  style=&#34;border-radius: 8px;&#34;  /&gt;


&lt;p&gt;We&amp;rsquo;ve completed the challenge! We have the plaintext of the document, and if we look at the middle line of the first page, we see that the flag for this challenge was &amp;ldquo;Machine Learning Sleigh Route Finder&amp;rdquo;. The completed python script can be found &lt;a href=&#34;https://github.com/ArchWizard56/holidayhack2019/blob/master/Recover%20Cleartext%20Document/decrypt.py&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If this write up was interesting or if you learned something, please drop me a line! It&amp;rsquo;s always great learning where I can improve or answering any questions about my methods.&lt;/p&gt;

        
        </description>
    </item>
    
  </channel>
</rss>