> For the complete documentation index, see [llms.txt](https://0xmedhat.gitbook.io/whoami/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xmedhat.gitbook.io/whoami/writesup/hacked-cyberdefenders.md).

# Hacked Cyberdefenders

Category : Digital Forensics  Medium " Linux FTK Disk"

* [Details](https://cyberdefenders.org/blueteam-ctf-challenges/71#nav-overview)

You have been called to analyze a compromised Linux web server. Figure out how the threat actor gained access, what modifications were applied to the system, and what persistent techniques were utilized. (e.g. backdoors, users, sessions, etc).

* [Questions](https://cyberdefenders.org/blueteam-ctf-challenges/71#nav-questions)

#### Q1 What is the system timezone?

We Can found it the `/etc/timezone` file

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FYvY9xZB9JitWAastO9Xu%2Fimage.png?alt=media&amp;token=62ae60b3-1c66-4f43-a2d5-59e8c13472f4" alt=""><figcaption></figcaption></figure>

**Ans : Europe/Brussels**

#### Q2 Who was the last user to log in to the system?

We can find  it in auth file on: `/var/log/auth.log`

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FmdKOLWKqXREpi6TQxgp4%2Fimage.png?alt=media&amp;token=76f43dad-8862-48b7-93a1-0f365877671c" alt=""><figcaption><p>57708Accepted password for mail from 192.168.210.131 port 57708 ssh2</p></figcaption></figure>

**Ans : mail**

#### Q3 What was the source port the user 'mail' connected from?

from the priv screen we can found it the answer  **"57708"**

#### Q4 How long was the last session for user 'mail'? (Minutes only)

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FLRVITuhgfOSLJ0ksfCH8%2Fimage.png?alt=media&amp;token=fd22ec48-31ec-4456-b739-9a47c7804734" alt=""><figcaption></figcaption></figure>

We can found the last session started at 13:23:34 and finished at 13:24:11\
then it's just 1  minute

\
**Ans : 1**&#x20;

#### Q5 Which server service did the last user use to log in to the system?

in the last screen we can found **sshd**

**Ans : sshd**&#x20;

#### Q6 What type of authentication attack was performed against the target machine

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FtY1Eypf4PYJzYCoKUG0W%2Fimage.png?alt=media&amp;token=adaf6666-2d7e-432a-800a-3c2619fd29d8" alt=""><figcaption></figcaption></figure>

In the same file We found it's many failled attemped okay it's bruteforce!

&#x20;**Ans : brute-force**

**Q7 How many IP addresses are listed in the '/var/log/lastlog' file?**

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FLKxDqSJDME4MRQH0gJQo%2Fimage.png?alt=media&amp;token=2b153996-ccdf-4211-a66b-ac2c03312d66" alt=""><figcaption><p>192.168.131- 192.168.56</p></figcaption></figure>

**Ans : 2**&#x20;

#### Q8 How many users have a login shell?

Users Having shell using **/bin/bash**

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FMJu93Q7w7MXYrTnqHh5Y%2Fimage.png?alt=media&amp;token=c21a270b-9b28-4e59-9931-cd90defefebc" alt=""><figcaption></figcaption></figure>

**Ans : 5**

#### Q9 What is the password of the mail user?

We can found password of email user in&#x20;

<mark style="color:red;">/etc/shadow</mark><br>

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FMBozp0FhxMlAhgmchaIJ%2Fimage.png?alt=media&amp;token=5a411257-def8-4709-8968-1e50259ec776" alt=""><figcaption></figcaption></figure>

```
sudo john --wordlist==/usr/share/rockyou.txt passwd.txt

```

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2Fqd2Ml5uaw5QKmHmtMjSV%2Fimage.png?alt=media&amp;token=c97e3f51-6ded-4937-99fc-0770da3909cc" alt=""><figcaption></figcaption></figure>

**Ans : forensics**

#### Q10 Which user account was created by the attacker?

Back to auth.log \
searching for useradd command we can found it&#x20;

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FRa0IuEYOVNSm9s5RS7HR%2Fimage.png?alt=media&amp;token=3af75e4a-ae47-497d-984d-776ed7fc74e2" alt=""><figcaption><p>php</p></figcaption></figure>

**Ans : php**&#x20;

#### Q11 How many user groups exist on the machine?

we can found group in `etc/group`&#x20;

open it to count&#x20;

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FvuNhHTBH0jyYrjC6EVip%2Fimage.png?alt=media&amp;token=31cfa490-5ebe-43c8-957d-37140d99804a" alt=""><figcaption><p>lin 58</p></figcaption></figure>

**Ans : 58**

#### Q12 How many users have sudo access?

in the same file searching for <mark style="color:blue;">sudo</mark>

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2Fqz9C37CctYFqTnJiFaxD%2Fimage.png?alt=media&amp;token=cea8566b-980a-4953-ad04-e7d78592615c" alt=""><figcaption><p>php,mail</p></figcaption></figure>

**Ans : 2**

#### Q13 What is the home directory of the PHP user?

From Q10 When the attacker created the user PHP,

&#x20;its home directory was <mark style="color:purple;">/usr/php</mark>

**Ans :   /usr/php**

#### Q14 What command did the attacker use to gain root privilege? (Answer contains two spaces).

We know from the prev Qusetions that the attacker logged in as the user <mark style="color:red;">mail</mark> , we find the it's home direcotry at: <mark style="color:red;">/var/mail</mark> &#x20;

let's investigate it's bash history

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FBxH9PvSztQwLnT30Iu5Q%2Fimage.png?alt=media&amp;token=a1b1fdcc-be6f-4a1e-bde4-a594f4270e76" alt=""><figcaption><p>sudo su -</p></figcaption></figure>

**Ans : sudo su -**

####

#### Q15 Which file did the user 'root' delete?

let's check root’s bash history file&#x20;

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FPpl6FbfE4lJr1Pj3hIqo%2Fimage.png?alt=media&amp;token=42ba3f13-48b0-440e-8fee-7b991f4deaa1" alt=""><figcaption><p>rm 37292.c</p></figcaption></figure>

**Ans : 37292.c**

#### Q16 Recover the deleted file, open it and extract the exploit author name.

After some minutes I searching in /tmp

After i clicked on it Window defender running ")

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FQ3vAUJxn7ls0IYLhE0Df%2Fimage.png?alt=media&amp;token=36fd3c06-debe-405f-b4d6-b0209620fffe" alt=""><figcaption></figcaption></figure>

After that search for the CVE in exploit-db:

<br>

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2F6YA1jqUJwh5lbBTsdNUI%2Fimage.png?alt=media&amp;token=e0264bb3-d5a0-467e-b46c-22e70476c3f7" alt=""><figcaption><p>Exploit Author: rebel</p></figcaption></figure>

\
**Ans : rebel**

#### Q17 What is the content management system (CMS) installed on the machine?

it's found in etc

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FDWDPMX2Q3ZGM5jkjyk5a%2Fimage.png?alt=media&amp;token=d4cd4b80-4629-4279-b8c6-c967bc294116" alt=""><figcaption><p>drupal opensource CMS</p></figcaption></figure>

**Ans : drupal**&#x20;

#### Q18 What is the version of the CMS installed on the machine?

By helping of chatgpt we can found the version of Drupal Cms in info files found in /var/www/html/

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2F9Y0HVj0s7YC7pq5dDk7E%2Fimage.png?alt=media&amp;token=dc63302c-7cb5-4f92-aafe-5052341ca0e5" alt=""><figcaption><p>7.26</p></figcaption></figure>

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FYmPswLQpPtyBkvy9uexP%2Fimage.png?alt=media&amp;token=188a5e32-4f07-4033-b289-b86677ec2b4c" alt=""><figcaption></figcaption></figure>

**Ans : 7.26**

#### Q19 Which port was listening to receive the attacker's reverse shell?

From the question 6 we can found the attacker ip [192.168.210.131](http://192.168.210.131/)

we can go to <mark style="color:red;">access.log</mark>&#x20;

and grep it&#x20;

we found decoded post request

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2FyAjn1CISBtKGW6WrSPem%2Fimage.png?alt=media&amp;token=0f013177-1f97-418f-8258-a302fb89a5f1" alt=""><figcaption><p>decodebase64</p></figcaption></figure>

let's going to cyberchief

<figure><img src="https://2672868225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MRLWF7BP-xoZbu8kb7J%2Fuploads%2F4KViQes0XMiHlGQJMkPB%2Fimage.png?alt=media&amp;token=957e6136-4116-4990-83a9-96ed2d4cac7f" alt=""><figcaption><p>$port = 4444</p></figcaption></figure>

**Ans : 4444**

We fininsed , Thank UUUUUUU for reading  ❤🥰
