<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://wiki.zenk-security.com/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://wiki.zenk-security.com/feed.php">
        <title>Zenk - Security ndhquals2015</title>
        <description></description>
        <link>http://wiki.zenk-security.com/</link>
        <image rdf:resource="http://wiki.zenk-security.com/lib/tpl/dokuwiki/images/favicon.ico" />
       <dc:date>2026-05-04T01:29:31+02:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:bpythonastic&amp;rev=1428245703&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:clark_kent&amp;rev=1428246082&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:cooper&amp;rev=1428240605&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:crackme_prime&amp;rev=1428278519&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:facebox&amp;rev=1428322561&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:facesec&amp;rev=1491744837&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:game_of_life&amp;rev=1428237976&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:mass_surveillance_software&amp;rev=1428251527&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:private&amp;rev=1491744837&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:raptor&amp;rev=1491744837&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:secureauth&amp;rev=1428238303&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:superman&amp;rev=1428246172&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:updator&amp;rev=1428404442&amp;do=diff"/>
                <rdf:li rdf:resource="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:weshgrow&amp;rev=1491744837&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://wiki.zenk-security.com/lib/tpl/dokuwiki/images/favicon.ico">
        <title>Zenk - Security</title>
        <link>http://wiki.zenk-security.com/</link>
        <url>http://wiki.zenk-security.com/lib/tpl/dokuwiki/images/favicon.ico</url>
    </image>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:bpythonastic&amp;rev=1428245703&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-05T16:55:03+02:00</dc:date>
        <title>ndhquals2015:bpythonastic</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:bpythonastic&amp;rev=1428245703&amp;do=diff</link>
        <description>Bpythonastic (Forensic300)

lien pour télécharger l'archive : &lt;http://repo.zenk-security.com/ctfs/ndh2k15/Bpythonastic.tar.gz&gt;

Après avoir extrait l'archive, on se retrouve face à un fichier “chall.raw”. 

On comprend rapidement que ce fichier est un dump mémoire d'une machine tournant sur linux. En effet, “dump.raw” contient plein de fichiers de différentes sortes et un coup de string nous donne la version exacte de la distribution linux utilisée :</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:clark_kent&amp;rev=1428246082&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-05T17:01:22+02:00</dc:date>
        <title>ndhquals2015:clark_kent</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:clark_kent&amp;rev=1428246082&amp;do=diff</link>
        <description>Clark Kent (Reverse150)

lien pour télécharger l'archive : &lt;http://repo.zenk-security.com/ctfs/ndh2k15/clark.tar.gz&gt;

Après extraction de l'archive de l'épreuve, on a un fichier texte “Clark.txt” contenant une citation de Clark Ken et un binaire linux 32-bit.</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:cooper&amp;rev=1428240605&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-05T15:30:05+02:00</dc:date>
        <title>ndhquals2015:cooper</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:cooper&amp;rev=1428240605&amp;do=diff</link>
        <description>Enoncé :
  &quot;I am not crazy, my mother had me tested.&quot; (Sheldon)
  
  What did Sheldon ... huh sorry, Dr. Cooper really mean?
  
  Score
      300
  Link
      http://static.challs.nuitduhack.com/Cooper.tar.gz 
      
L'archive contient un exécutable PE 32 bits s'appellant “Cooper.exe”.</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:crackme_prime&amp;rev=1428278519&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-06T02:01:59+02:00</dc:date>
        <title>ndhquals2015:crackme_prime</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:crackme_prime&amp;rev=1428278519&amp;do=diff</link>
        <description>Enoncé : 
  &quot;I am Optimus Prime, and I send this message to any surviving Autobots taking refuge among the stars. 
  We are here, we are waiting.&quot;
  Keygen me, I'm the Prime.
  Validate your serial here : http://crackmeprime.challs.nuitduhack.com/
  Score
      150
  Link
      http://static.challs.nuitduhack.com/prime.tar.gz 
      
On récupère davantage d'informations sur le fichier du challenge :</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:facebox&amp;rev=1428322561&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-06T14:16:01+02:00</dc:date>
        <title>ndhquals2015:facebox</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:facebox&amp;rev=1428322561&amp;do=diff</link>
        <description>Web        100 points      &lt;http://quals.nuitduhack.com/challenges/view/10&gt;
&lt;http://prod.facebox.challs.nuitduhack.com/&gt;

Énoncé

“A shady company decided to write their own software for storing files in the cloud.

No no no, this is OUR filebox. We decline any responsability in the usage of our filebox. In any event your files get lost, trashed, stolen or spy on : it's your fault, not ours.”

You are investigating on the security of their cloud storage as it might have disastrous consequences i…</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:facesec&amp;rev=1491744837&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-04-09T15:33:57+02:00</dc:date>
        <title>ndhquals2015:facesec</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:facesec&amp;rev=1491744837&amp;do=diff</link>
        <description>Web        100 points    &lt;http://quals.nuitduhack.com/challenges/view/11&gt;

&lt;http://facesec.challs.nuitduhack.com/&gt;

Énoncé

“Hello there,

We are looking for a developer or security consultant to secure our filebox system. We stumbled upon your LinkedIn profile and it seems like you would be a perfect candidate for this job. Could you please send us your CV and Motivation letter?</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:game_of_life&amp;rev=1428237976&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-05T14:46:16+02:00</dc:date>
        <title>ndhquals2015:game_of_life</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:game_of_life&amp;rev=1428237976&amp;do=diff</link>
        <description>Enoncé : 
  &quot;We're born alone, we live alone, we die alone. Only through our love and friendship can we create the illusion for the moment that we're not alone.&quot; (Orson Orwell)
  Cells cells cells, the basis of life. Don't let them die and tell us their secret.
  Score
      150
  Link
      http://static.challs.nuitduhack.com/GOL.tar.gz 
L'archive contient un cipher.txt illisible, et un script Python suivant :</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:mass_surveillance_software&amp;rev=1428251527&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-05T18:32:07+02:00</dc:date>
        <title>ndhquals2015:mass_surveillance_software</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:mass_surveillance_software&amp;rev=1428251527&amp;do=diff</link>
        <description>Mass Surveillance Software

lien pour télécharger l'archive : &lt;http://repo.zenk-security.com/ctfs/ndh2k15/mass.tar.gz&gt;

Unpack

Le binaire était packé avec un upx modifié, il suffisait donc de voir le pushad à 0x004460A0, de chercher le popad qui est à 0x00446235 et le tail jump pas très loin (à 0x00446243) qui pointe vers l'OEP : 0x004015A7</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:private&amp;rev=1491744837&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-04-09T15:33:57+02:00</dc:date>
        <title>ndhquals2015:private</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:private&amp;rev=1491744837&amp;do=diff</link>
        <description>Forensic       100 points      &lt;http://quals.nuitduhack.com/challenges/view/19&gt;

Énoncé

“The quiet you are, the more you are able to ear”


Link: &lt;http://static.challs.nuitduhack.com/Private.tar.gz&gt;


Challenge

On a affaire un fichier pcapng :</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:raptor&amp;rev=1491744837&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-04-09T15:33:57+02:00</dc:date>
        <title>ndhquals2015:raptor</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:raptor&amp;rev=1491744837&amp;do=diff</link>
        <description>Misc       400 points      &lt;http://quals.nuitduhack.com/challenges/view/12&gt;

Énoncé

Aucun énoncé, aucune précision ; seul un lien est présent : raptor.challs.nuitduhack.com:4142

Challenge

Connectons-nous :
    [plo@hyperion Misc]$ nc raptor.challs.nuitduhack.com 4142
    ~ » Welcome to the Raptor/1.0 Information Exchange Server
    ~ » You are anonymous - Read only access !
    Available commands :
    +----------+-----------------+-------------------------------+-----------------------------…</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:secureauth&amp;rev=1428238303&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-05T14:51:43+02:00</dc:date>
        <title>ndhquals2015:secureauth</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:secureauth&amp;rev=1428238303&amp;do=diff</link>
        <description>Enoncé : 
  &quot;There is a building. Inside this building there is a level where no elevator can go, and no stair can reach. This level is filled with doors. These doors lead to many places. Hidden places. But one door is special. One door leads to the source.&quot; (The Keymaker)
  Find the key. Open the door.
  Static client @ http://static.challs.nuitduhack.com/SecureAuthClient.tar.gz
  Score
      350
  Link
      secureauth.challs.nuitduhack.com:4241 
L'archive contient le script Python suivant :</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:superman&amp;rev=1428246172&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-05T17:02:52+02:00</dc:date>
        <title>ndhquals2015:superman</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:superman&amp;rev=1428246172&amp;do=diff</link>
        <description>Superman (Reverse500)

lien pour télécharger l'archive : &lt;http://repo.zenk-security.com/ctfs/ndh2k15/superman.tar.gz&gt;

Cette épreuve est construite de la même façon que Clark Kent, on a aussi le header elf à corriger, un ptrace, un calcul de checksum sur le code et une vérification si on est root ou pas.</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:updator&amp;rev=1428404442&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2015-04-07T13:00:42+02:00</dc:date>
        <title>ndhquals2015:updator</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:updator&amp;rev=1428404442&amp;do=diff</link>
        <description>Exploit       200 points      &lt;http://quals.nuitduhack.com/challenges/view/9&gt;

&lt;http://updator.challs.nuitduhack.com/&gt;

Énoncé

Unhackable : “Not hackable; that cannot be hacked or broken into.”

We manage updates and thus have fixes, this is not a PS3 as it is unhackable ... or is it?</description>
    </item>
    <item rdf:about="http://wiki.zenk-security.com/doku.php?id=ndhquals2015:weshgrow&amp;rev=1491744837&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2017-04-09T15:33:57+02:00</dc:date>
        <title>ndhquals2015:weshgrow</title>
        <link>http://wiki.zenk-security.com/doku.php?id=ndhquals2015:weshgrow&amp;rev=1491744837&amp;do=diff</link>
        <description>Enoncé :
  &quot;HMAC MD5 or HMAC SHA1 are sooo obsoletes and sooo old. And they are clunky and sooo slooow! That is why, from today, we are introducing to the world a new HMAC algorithm. The best one invented ever : it's light, it's fast and it's secure, well it's the BHE or short for 'Best Hash Ever'.&quot; (C.E.C. - Cryptography Experts Company) Prove them wrong.
  
Nous pouvions accéder à l'épreuve via l'URL suivante:</description>
    </item>
</rdf:RDF>
