Positive Hack Days , . : . , 2017 , , .
GreatIOT. IoT-. , - , , , CEO . , .
1. Find information about the missing designer
1.1. Nobody at the company of greatiot.phdays.com could even say what his first and last name is. Maybe you can find it?
, :
logo-vender.png.
, , XMP- Adobe:
! , . , e-mail: , , mail.greatiot.phdays.com, , , .Twitter ( Instagram):
, :
astupinin@greatiot.phdays.com
. :
: Alex Stupinin
: 11
1.2. Most excellent. We have logs from his fitness tracker and we need to know where hes spent his evenings after work. (Name in uppercase)
Facebook, Foursquare (SwarmApp), , :
, fitbit_log_07_05.cvs
, , , , . , . ~700800 . Foursquare, 500 . , .
: PRAHA
: 9
2. Lead IoT developer
2.1. We have only a photo of his wife from his desktop background: yadi.sk/i/wIMhX59h3J5ufA. Find the IP address of the developer's personal server.
, , , (photo_2017-04-25_15-46-33.jpg). : . Instagram 25 , snradar.azurewebsites.net:
!
Instagram elena91u:
, softcodermax, Pastebin:
: 188.166.76.66
: 18
2.2 Apparently the developers used team chat but often head to discuss things via VoIP. Get the address of the VoIP gateway.
- sitemap.xml, "/logs.php":
logs.php , logdate is missing. last log date 20170428,
188.166.76.66/logs.php?logdate=20170428 access- . , - Skype Referer:
64.19.23.198 - - [26/Apr/2017:08:26:09 +0000] "GET / HTTP/1.1" 200 2613 "https://join.skype.com/aMxdupsIlSgI" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36"
Skype, VoIP-.
: voip-gw-home-198.phdays.com
: 3
2.3 Not bad. Maybe you can also find out the last person he called?
voip-gw-home-198.phdays.com HTML-, DblTek:
, Telnet , :
:
https://github.com/JacobMisirian/DblTekGoIPPwn.
challenge-response , sqlite- voip:
: +79262128506
: 3
3. GreatIOT evangelist and hipster
3.1. All we could find is his email address: digitalmane@yandex.com. But information about his router is stored somewhere Uncover its URL! (Format: hostname.com/page/)
, , Favorite artist. , , SoundCloud Last.fm. , Google :
GHOSTEMANE, . , , URL. , , , , . old1337.
: greatiot.phdays.com/old1337/
: 66*
* - , .
3.2. Find the IP address of the router, will you?
old1337, :
Google , , , (HEX, netcat), how_to_connect.rar. RAR NTFS-, OOXML Zone.Identifier:$DATA, , , Text.Information:$DATA, IP- :
: 178.62.218.236
: 4
3.3. Interesting He doesnt look much like a hipster, especially with a name like that. Find out his first and last name.
: Configuration Status & Logs:
XML. , : XML External Entity. ? Status & Logs :
XXE , Out-of-Band
. /etc/passwd , .pcap php://filter, :
www.idontplaydarts.com/2011/02/using-php-filter-for-local-file-inclusion
:
Base64 , :
, , : Panteleev. . , , , . , , :
, Facebook, .
: Isaac Panteleev
: 2
4. The Secretary is hiding something
4.1. We could find only part of a phone number, but her e-mail is brintet@protonmail.com. Have any ideas on how to find the full version? +7985134****
, , , . : PayPal, :
: +79851348961
: 19
4.2. Surely it wont be hard for you to find out her first and last name?
, , , , : WhatsApp, Viber, Telegram, :
: Maria Brintet
: 14
5. Missing Man #1
5.1. He has a secret related to this wallet LMksJQ3GrHXDSMjwEvPAEJsaXS7agq6DaQ. Find out where he transferred all this money to.
, Litecoin. , Litecoin, :
: LM33p4m3ZDk5rs1BjkWUvEw3UWWiaH2u2L
: 23
5.2. Find out where he is.
, , Google , :
jp.karter7@gmail.com
:
: Severalls
: 12
6. Why so many tears?
6.1. All we could find is the developer's account and a CloudPets recording: yadi.sk/d/qTNjZYj63J5vHB. Overhear his secret.
cloudpets.7z, CloudPets, AWS , (https://www.troyhunt.com/data-from-connected-cloudpets-teddy-bears-leaked-and-ransomed-exposing-kids-voice-messages/).
, 2:44, , (, Sonic Visualiser), , . , , .
: GHgq217$#178@k12/
: 5
7. Pythons crawling everywhere
7.1. Get the developer's Twitter login. There's a web service here: devsecure-srv139.phdays.com
devsecure-srv139.phdays.com, . , CloudFlare:
CF-RAY:3519eafdb3a94e84-DME
Server:cloudflare-nginx
Google IP-:
, CA ( , Cloudbleed):
CA (ca.key, ca.crt) :
openssl genrsa -out client.key 1024
openssl req -new -key client.key -out client.csr
openssl x509 -req -days 365 -in client.csr -CA ca.crt -CAkey ca.key -set_serial 3137 -out client.crt
openssl pkcs12 -export -clcerts -in client.crt -inkey client.key -out client.p12
, . Twitter- :
: MontyPythonist
: 6
8.System administrator
8.1. We found the token d91496dfcaad93f974a715fb58abeeb0 and VDS 188.226.148.233. Try to find the sysadmin's github account.
, API http://188.226.148.233/api/tasks, . GET-,
JSON, GitHub- anneximous:
: anneximous
: 12
8.2. Looks like a home router See if you dig up something interesting.
Google anneximous :
IP- , camera_contol.html left.js.
IP- 188.166.30.118, 8080 IP-, camera_control.html, :
left.js. :
function Call(xml) {
if (gVar.httpver == "https") {
setCookie("snapcmd", gVar.httpver + "://" + gVar.ip + ":" + mult_https_port[IFs] + "/cgi-bin/CGIProxy.fcgi?" + (urlEncode("usr=" + gVar.user + "&pwd=" + gVar.passwd + "&cmd=snapPicture")));
}
:
http://188.166.30.118:8080/cgi-bin/CGIProxy.fcgi?usr%3Dphdaysiot%26pwd%3Dphdaysiot7%26cmd%3DsnapPicture
, . , :
:
188.166.30.118:8080/cgi-bin/CGIProxy.fcgi?usr%3Dphdaysiot%26pwd%3Dphdaysiot7%26cmd%3DptzMoveLeft : ptzMoveDown, ptzMoveUp, ptzMoveRight : ptzStopRun. :
: AnneximousBADIOT
: 7
66 . noyer ( ) , . AVictor ( ), mkhazov ( ).
1 |
noyer |
16 |
2 |
AVictor |
13 |
3 |
mkhazov |
12 |
4 |
crackitdown |
10 |
5 |
topol |
9 |
6 |
Ursus |
9 |
7 |
x010 |
8 |
8 |
buzz |
8 |
9 |
ThreatIntel |
8 |
10 |
mattgrow |
5 |
https://habrahabr.ru/post/333600/