data:image/s3,"s3://crabby-images/af10f/af10f18e4f9e20c1079ae37ecfef6bd56a2a29f8" alt=""
Level10
Use the level10 password “interesting to hack” to access the level10 account and check the hint.
data:image/s3,"s3://crabby-images/8b492/8b49262a8ab68e3f9f94e003258263633e62f756" alt=""
data:image/s3,"s3://crabby-images/8b492/8b49262a8ab68e3f9f94e003258263633e62f756" alt=""
Since there is no information on the attack target file in the hint, I used the find command to search for the existence of the file with level11 privilege.
data:image/s3,"s3://crabby-images/b3400/b3400c331ff2c3e61f4f11985cc0ba3e05820441" alt=""
but, the file is not founded. Also, there is a directory called program in the home directory of level10, but it can not be checked because it is owned by root.
data:image/s3,"s3://crabby-images/8f914/8f91471e7a7a2bfc29e915c6ba287674ad8ecead" alt=""
I checked the rc.local file because there might be a setting in the file that registers the program to start automatically when the system starts.
data:image/s3,"s3://crabby-images/fd8c9/fd8c99d0cea35199d13ae59357e2ea7096063768" alt=""
I can see that there is a program named level10. I tried the ps command to see if it is a running process.
data:image/s3,"s3://crabby-images/3a2a4/3a2a40cdfada35ae179ca45ac19d1f0986f7f29b" alt=""
Since there are no running process named level10, This program is a simple process, not a daemon type. A daemon is a process that runs repeatedly, and a simple process is a process that runs only once.The shared memory in the hint is used in the following way:
data:image/s3,"s3://crabby-images/9b5a1/9b5a11c24a0a7f7ea71cda98374d4f13784c97bc" alt=""
When I write the code using the conditions in question, I can write as follows.
data:image/s3,"s3://crabby-images/c9398/c93988ee4bab9a39cb2f30517c873ea44d9b025b" alt=""
When I compile the file and run it, I can get the level11 password as follows.
data:image/s3,"s3://crabby-images/c4ad1/c4ad188a16a14c9573ede47e7cdb830ae6bc2dbb" alt=""
No comments:
Post a Comment