-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


PHDays:

, 18 2017 . 14:17 +
image

Positive Hack Days , . : . , 2017 , , .

GreatIOT. IoT-. , - , , , CEO . , .

1. Find information about the missing designer


1.1. Nobody at the company of greatiot.phdays.com could even say what his first and last name is. Maybe you can find it?


, :

image

logo-vender.png.

image

, , XMP- Adobe:

image

! , . , e-mail: , , mail.greatiot.phdays.com, , , .Twitter ( Instagram):

image
image

, : astupinin@greatiot.phdays.com. :

image

: Alex Stupinin
: 11

1.2. Most excellent. We have logs from his fitness tracker and we need to know where hes spent his evenings after work. (Name in uppercase)


Facebook, Foursquare (SwarmApp), , :

image

, fitbit_log_07_05.cvs

image

, , , , . , . ~700800 . Foursquare, 500 . , .

: PRAHA
: 9

2. Lead IoT developer


2.1. We have only a photo of his wife from his desktop background: yadi.sk/i/wIMhX59h3J5ufA. Find the IP address of the developer's personal server.


, , , (photo_2017-04-25_15-46-33.jpg). : . Instagram 25 , snradar.azurewebsites.net:

image

!

image

Instagram elena91u:

image

, softcodermax, Pastebin:

image

: 188.166.76.66
: 18

2.2 Apparently the developers used team chat but often head to discuss things via VoIP. Get the address of the VoIP gateway.


- sitemap.xml, "/logs.php":

image

logs.php , logdate is missing. last log date 20170428, 188.166.76.66/logs.php?logdate=20170428 access- . , - Skype Referer:

64.19.23.198 - - [26/Apr/2017:08:26:09 +0000] "GET / HTTP/1.1" 200 2613 "https://join.skype.com/aMxdupsIlSgI" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36" 

Skype, VoIP-.

: voip-gw-home-198.phdays.com
: 3

2.3 Not bad. Maybe you can also find out the last person he called?


voip-gw-home-198.phdays.com HTML-, DblTek:

image

, Telnet , :

image

: https://github.com/JacobMisirian/DblTekGoIPPwn.

challenge-response , sqlite- voip:

image

: +79262128506
: 3

3. GreatIOT evangelist and hipster


3.1. All we could find is his email address: digitalmane@yandex.com. But information about his router is stored somewhere Uncover its URL! (Format: hostname.com/page/)


, , Favorite artist. , , SoundCloud Last.fm. , Google :

image

GHOSTEMANE, . , , URL. , , , , . old1337.

: greatiot.phdays.com/old1337/
: 66*

* - , .

3.2. Find the IP address of the router, will you?


old1337, :

image

Google , , , (HEX, netcat), how_to_connect.rar. RAR NTFS-, OOXML Zone.Identifier:$DATA, , , Text.Information:$DATA, IP- :

image

: 178.62.218.236
: 4

3.3. Interesting He doesnt look much like a hipster, especially with a name like that. Find out his first and last name.


: Configuration Status & Logs:

image

XML. , : XML External Entity. ? Status & Logs :

image

XXE , Out-of-Band . /etc/passwd , .pcap php://filter, : www.idontplaydarts.com/2011/02/using-php-filter-for-local-file-inclusion

:

image

Base64 , :

image

image

, , : Panteleev. . , , , . , , :

image

, Facebook, .

: Isaac Panteleev
: 2

4. The Secretary is hiding something


4.1. We could find only part of a phone number, but her e-mail is brintet@protonmail.com. Have any ideas on how to find the full version? +7985134****


, , , . : PayPal, :

image

: +79851348961
: 19

4.2. Surely it wont be hard for you to find out her first and last name?


, , , , : WhatsApp, Viber, Telegram, :

image

: Maria Brintet
: 14

5. Missing Man #1


5.1. He has a secret related to this wallet LMksJQ3GrHXDSMjwEvPAEJsaXS7agq6DaQ. Find out where he transferred all this money to.


, Litecoin. , Litecoin, :

image

: LM33p4m3ZDk5rs1BjkWUvEw3UWWiaH2u2L
: 23

5.2. Find out where he is.


, , Google , :

image

jp.karter7@gmail.com :

image

: Severalls
: 12

6. Why so many tears?


6.1. All we could find is the developer's account and a CloudPets recording: yadi.sk/d/qTNjZYj63J5vHB. Overhear his secret.


cloudpets.7z, CloudPets, AWS , (https://www.troyhunt.com/data-from-connected-cloudpets-teddy-bears-leaked-and-ransomed-exposing-kids-voice-messages/).

image

, 2:44, , (, Sonic Visualiser), , . , , .

: GHgq217$#178@k12/
: 5

7. Pythons crawling everywhere


7.1. Get the developer's Twitter login. There's a web service here: devsecure-srv139.phdays.com


devsecure-srv139.phdays.com, . , CloudFlare:

CF-RAY:3519eafdb3a94e84-DME
Server:cloudflare-nginx

Google IP-:

image

, CA ( , Cloudbleed):

image

CA (ca.key, ca.crt) :

openssl genrsa -out client.key 1024
openssl req -new -key client.key -out client.csr
openssl x509 -req -days 365 -in client.csr -CA ca.crt -CAkey ca.key -set_serial 3137 -out client.crt
openssl pkcs12 -export -clcerts -in client.crt -inkey client.key -out client.p12

, . Twitter- :

image

: MontyPythonist
: 6

8.System administrator


8.1. We found the token d91496dfcaad93f974a715fb58abeeb0 and VDS 188.226.148.233. Try to find the sysadmin's github account.


, API http://188.226.148.233/api/tasks, . GET-, JSON, GitHub- anneximous:

image

: anneximous
: 12

8.2. Looks like a home router See if you dig up something interesting.


Google anneximous :

image

IP- , camera_contol.html left.js.

image

IP- 188.166.30.118, 8080 IP-, camera_control.html, :

image

image

left.js. :

  function Call(xml) {
        if (gVar.httpver == "https") {
            setCookie("snapcmd", gVar.httpver + "://" + gVar.ip + ":" + mult_https_port[IFs] + "/cgi-bin/CGIProxy.fcgi?" + (urlEncode("usr=" + gVar.user + "&pwd=" + gVar.passwd + "&cmd=snapPicture")));
        }

:

http://188.166.30.118:8080/cgi-bin/CGIProxy.fcgi?usr%3Dphdaysiot%26pwd%3Dphdaysiot7%26cmd%3DsnapPicture

, . , :

image

:

image

188.166.30.118:8080/cgi-bin/CGIProxy.fcgi?usr%3Dphdaysiot%26pwd%3Dphdaysiot7%26cmd%3DptzMoveLeft : ptzMoveDown, ptzMoveUp, ptzMoveRight : ptzStopRun. :

image

: AnneximousBADIOT
: 7


66 . noyer ( ) , . AVictor ( ), mkhazov ( ).

1 noyer 16
2 AVictor 13
3 mkhazov 12
4 crackitdown 10
5 topol 9
6 Ursus 9
7 x010 8
8 buzz 8
9 ThreatIntel 8
10 mattgrow 5
Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/333600/

:  

: [1] []
 

:
: 

: ( )

:

  URL