{"id":35235,"date":"2018-02-20T23:50:30","date_gmt":"2018-02-20T23:50:30","guid":{"rendered":"https:\/\/writemyessayfree.com\/describe-all-14-vulnerabilities-exposed-in-the-security-first-lab-in-layman-terms-and-explain-why-each-step-is-important-without-using-the-objective-listed"},"modified":"2017-08-16T06:31:17","modified_gmt":"2017-08-16T06:31:17","slug":"describe-all-14-vulnerabilities-exposed-in-the-security-first-lab-in-layman-terms-and-explain-why-each-step-is-important-without-using-the-objective-listed","status":"publish","type":"post","link":"https:\/\/www.benedictsol.com\/blogs\/describe-all-14-vulnerabilities-exposed-in-the-security-first-lab-in-layman-terms-and-explain-why-each-step-is-important-without-using-the-objective-listed\/","title":{"rendered":"Describe all 14 vulnerabilities exposed in the Security First lab in layman terms and explain why each step is important without using the objective listed"},"content":{"rendered":"<div class=\"the_content_wrapper\">\n<p>SecurityFirst Competition v2.1<\/p>\n<p>Competition Information. 1<\/p>\n<p>Background. 1<\/p>\n<p>Objectives. 1<\/p>\n<p>Rules. 2<\/p>\n<p>Reference. 3<\/p>\n<p>Users. 3<\/p>\n<p>Goals. 3<\/p>\n<p>Walkthrough. 6<\/p>\n<p>Forward. 6<\/p>\n<p>Section 1:&nbsp; Gaining Access to the Database. 6<\/p>\n<p>Section 2:&nbsp; Logging In As a Customer. 7<\/p>\n<p>Section 3:&nbsp; Stealing the Money. 8<\/p>\n<p>Section 4:&nbsp; Leaving a Mark. 9<\/p>\n<h1><\/h1>\n<h1>Competition Information<\/h1>\n<h2>Background<\/h2>\n<p>This competition is a reincarnation of previous efforts at UNCC to provide students with an engaging, hands-on test of their knowledge.&nbsp; An older project, CyberWars, was used for years as a final project in Vulnerability Assessment and System Assurance to test student\u2019s knowledge of network and operating system security. &nbsp;However, when the decision was made to split the course into two separate classes, one of which focusing specifically on web-based vulnerabilities, a replacement competition was needed.&nbsp; Although the initial iteration of SecurityFirst was too simple and unrealistic, inspiration was drawn from UCSB\u2019s annual International CTF competition in 2008.&nbsp; Using those design ideas as a starting point, construction of this version of SecurityFirst began.<\/p>\n<h2>Objectives<\/h2>\n<p>The overarching objective presented to contestants of this competition is to be the first to log in as a financial manager and transfer funds between the two specified accounts.&nbsp; In order to do this, contestants must find and exploit various web-based vulnerabilities as they work toward their ultimate goal.&nbsp; As a secondary objective, each vulnerability discovered and successfully exploited earns them points.<\/p>\n<p>By default, the accounts for the transfer are listed below.&nbsp; The amount transferred is unimportant and any number will be fine as the transfer is only simulated.<\/p>\n<p>Source account:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 109762820<br \/> Destination account:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 110806729<\/p>\n<p>During the competition you may need to crack MD5-hashed passwords you find. A script, md5crack, has been provided for attempting to brute-forcing crack MD5 password hashes. Simply enter \u201cmd5crack\u201d in a terminal to see the help guide with examples. Because brute-forcing can be a long and time consuming process, the following hints are given:<\/p>\n<ol>\n<li>One of the users has a weak password that is no longer than 3 characters.<\/li>\n<li>His or her password contains lowercase letters<\/li>\n<\/ol>\n<p>Use these hints when running md5crack. Remember, cracking a password isn\u2019t the only way into an account. Good luck!<\/p>\n<h2>Rules<\/h2>\n<ol>\n<li>The scope of the competition is discovering and exploiting web-based vulnerabilities of the SecurityFirst web application. Contestants are urged to use the phpMyAdmin and SquirrelMail web applications where applicable, but attacking these is against the rules.<\/li>\n<li>Outside the use of the provided password cracking tool, brute-force tools or methods are forbidden. Running scripts to attempt to log into any services will be considered an attempted denial of service attack and the contestant will be penalized or disqualified.<\/li>\n<li>The competition application is designed for use with multiple concurrent users and should not allow cross-contestant attacking. However, directly attacking other contestants by means outside of the web application is prohibited.<\/li>\n<li>Periodically judges may ask for you to demonstrate a vulnerability that you previously exploited. This is not social engineering; this is normal.<\/li>\n<li>Developing exercises like this one is very time consuming and many times the same competition is used multiple semesters, so please do not disclose vulnerabilities or hints to others.<\/li>\n<\/ol>\n<h1><\/h1>\n<h1>Reference<\/h1>\n<h2>SecurityFirst Users<\/h2>\n<table>\n<tbody>\n<tr>\n<td width=\"79\"><strong>Username<\/strong><\/td>\n<td width=\"78\"><strong>Password<\/strong><\/td>\n<td width=\"114\"><strong>Name<\/strong><\/td>\n<td width=\"168\"><strong>E-mail Address<\/strong><\/td>\n<td width=\"72\"><strong>Secret<\/strong><\/td>\n<td width=\"127\"><strong>Role<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"79\"><strong>tdunlin<\/strong><\/td>\n<td width=\"78\">G7qD3!Lv<\/td>\n<td width=\"114\">Thomas Dunlin<\/td>\n<td width=\"168\">tdunlin@fakemail.com<\/td>\n<td width=\"72\">Grant<\/td>\n<td width=\"127\">Customer<\/td>\n<\/tr>\n<tr>\n<td width=\"79\"><strong>khill<\/strong><\/td>\n<td width=\"78\">1cDz@oni<\/td>\n<td width=\"114\">Kaitlin Hill<\/td>\n<td width=\"168\">khill@fakemail.com<\/td>\n<td width=\"72\">Craig<\/td>\n<td width=\"127\">Customer<\/td>\n<\/tr>\n<tr>\n<td width=\"79\"><strong>smaslov<\/strong><\/td>\n<td width=\"78\">Ix0nW!Nr<\/td>\n<td width=\"114\">Sonya Maslov<\/td>\n<td width=\"168\">smaslov@fakemail.com<\/td>\n<td width=\"72\">Panin<\/td>\n<td width=\"127\">Customer<\/td>\n<\/tr>\n<tr>\n<td width=\"79\"><strong>fsmith<\/strong><\/td>\n<td width=\"78\">red<\/td>\n<td width=\"114\">Frank Smith<\/td>\n<td width=\"168\">fsmith@securityfirst.com<\/td>\n<td width=\"72\">Dunn<\/td>\n<td width=\"127\">Site Admin<\/td>\n<\/tr>\n<tr>\n<td width=\"79\"><strong>xwang<\/strong><\/td>\n<td width=\"78\">y@k6cQtj<\/td>\n<td width=\"114\">Xu Wang<\/td>\n<td width=\"168\">xwang@securityfirst.com<\/td>\n<td width=\"72\">Zheng<\/td>\n<td width=\"127\">Site Admin<\/td>\n<\/tr>\n<tr>\n<td width=\"79\"><strong>rscott<\/strong><\/td>\n<td width=\"78\">H9c!pJ6b<\/td>\n<td width=\"114\">Roger Scott<\/td>\n<td width=\"168\">rscott@securityfirst.com<\/td>\n<td width=\"72\">Heifner<\/td>\n<td width=\"127\">Financial Manager<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><\/h2>\n<table width=\"612\">\n<tbody>\n<tr>\n<td width=\"282\">\n<h2>MySQL Users<\/h2>\n<table>\n<tbody>\n<tr>\n<td width=\"119\"><strong>Username<\/strong><\/td>\n<td width=\"108\"><strong>Password<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"119\"><strong>login_manager<\/strong><\/td>\n<td width=\"108\">23sk!d0o<\/td>\n<\/tr>\n<tr>\n<td width=\"119\"><strong>competition<\/strong><\/td>\n<td width=\"108\">H4v3fo0n<\/td>\n<\/tr>\n<tr>\n<td width=\"119\"><strong>root<\/strong><\/td>\n<td width=\"108\">Sunr!se49ers<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<td width=\"330\">\n<h2>System\/Email Users<\/h2>\n<table width=\"208\">\n<tbody>\n<tr>\n<td width=\"94\"><strong>Username<\/strong><\/td>\n<td width=\"114\"><strong>Password<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"94\"><strong>hacker<\/strong><\/td>\n<td width=\"114\">1234<\/td>\n<\/tr>\n<tr>\n<td width=\"94\"><strong>sfadmin<\/strong><\/td>\n<td width=\"114\">Sunr!se49ers<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h2>Goals<\/h2>\n<table width=\"638\">\n<tbody>\n<tr>\n<td width=\"37\"><strong>ID<\/strong><\/td>\n<td width=\"246\"><strong>Location<\/strong><\/td>\n<td width=\"288\"><strong>Type<\/strong><\/td>\n<td width=\"67\"><strong>Points<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>100<\/strong><\/td>\n<td width=\"246\">\/site\/login.jsp<\/td>\n<td width=\"288\">Source Code Disclosure<\/td>\n<td width=\"67\">10<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>101<\/strong><\/td>\n<td width=\"246\">\/site\/login.jsp<\/td>\n<td width=\"288\">SQL Injection<\/td>\n<td width=\"67\">25<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>102<\/strong><\/td>\n<td width=\"246\">\/site\/login.jsp<\/td>\n<td width=\"288\">Insecure Authentication<\/td>\n<td width=\"67\">30<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>103<\/strong><\/td>\n<td width=\"246\">\/site\/login.jsp<\/td>\n<td width=\"288\">Cross-Site Scripting<\/td>\n<td width=\"67\">45<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>110<\/strong><\/td>\n<td width=\"246\">\/site\/faq.jsp<\/td>\n<td width=\"288\">Source Code Disclosure<\/td>\n<td width=\"67\">10<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>111<\/strong><\/td>\n<td width=\"246\">\/site\/faq.jsp<\/td>\n<td width=\"288\">Directory Traversal via Filter Evasion<\/td>\n<td width=\"67\">25<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>112<\/strong><\/td>\n<td width=\"246\">\/site\/faq.jsp<\/td>\n<td width=\"288\">Filter Evasion<\/td>\n<td width=\"67\">20<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>113<\/strong><\/td>\n<td width=\"246\">\/site\/faq.jsp<\/td>\n<td width=\"288\">Denial of Service<\/td>\n<td width=\"67\">60<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>120<\/strong><\/td>\n<td width=\"246\">Database<\/td>\n<td width=\"288\">Insecure Cryptographic Storage<\/td>\n<td width=\"67\">25<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>200<\/strong><\/td>\n<td width=\"246\">\/customers\/editcomment.jsp<\/td>\n<td width=\"288\">Request Variable Manipulation<\/td>\n<td width=\"67\">15<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>201<\/strong><\/td>\n<td width=\"246\">\/customers\/editcomment.jsp<\/td>\n<td width=\"288\">Cross-Site Scripting<\/td>\n<td width=\"67\">10<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>300<\/strong><\/td>\n<td width=\"246\">\/secure\/siteadmin\/index.jsp<\/td>\n<td width=\"288\">Weak Password Hash Cracking<\/td>\n<td width=\"67\">30<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>310<\/strong><\/td>\n<td width=\"246\">\/secure\/siteadmin\/active_users.jsp<\/td>\n<td width=\"288\">Session Hijacking<\/td>\n<td width=\"67\">35<\/td>\n<\/tr>\n<tr>\n<td width=\"37\"><strong>400<\/strong><\/td>\n<td width=\"246\">\/secure\/financial_manager\/<\/p>\n<p>transfer_funds.jsp<\/p>\n<\/td>\n<td width=\"288\">Weak Password Management Policy<\/td>\n<td width=\"67\">75<\/td>\n<\/tr>\n<tr>\n<td colspan=\"3\" width=\"571\"><strong>Total:<\/strong><\/td>\n<td width=\"67\">415<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<h3>100<\/h3>\n<p>By removing one or both of the POST request variables (\u201cusername\u201d and \u201cpassword\u201d), an un-handled exception is thrown.&nbsp; The result of this NullPointerException is the displaying of a small portion of the relevant page code via a standard Tomcat 500 Error page.&nbsp; The benefit of the displayed code is to learn the location of the include file that contains the database connection credential information.&nbsp; This should be used in conjunction with Goals 111 and 112.<\/p>\n<h3>101<\/h3>\n<p>This is a simple SQL Injection vulnerability that allows a user to enter a basic login bypass SQL Injection (e.g. <strong>\u2018 OR \u2018a\u2019=\u2019a<\/strong>) in order to login as a user.&nbsp; More advanced injections will allow the user to attempt to log into a specific user and not just the first in the database.&nbsp; This will only allow access a customer\u2019s account and not to a higher-privileged account (admins and managers must log in through the \/secure\/login.jsp).<\/p>\n<h3>102<\/h3>\n<p>Because the login page simply hashes the password without any salting before sending it to the server, a password hash found in the database could be replayed with a tool like Tamper Data that modifies POST request variables after the form submit takes place.&nbsp; This requires successfully gaining access to the MySQL database.&nbsp; If real victim users were using this web application on your network, it would be possible to obtain a hash by packet sniffing their login attempts.<\/p>\n<h3>103<\/h3>\n<p>Upon failing to correctly log in on the&nbsp; login page, users are informed that their activity has been logged.&nbsp; This log is viewed by site admins at \/secure\/siteadmin\/logviewer.jsp.&nbsp; The log entries for failed log-ins contains the username of the attempted log-in and because these are neither filtered nor encoded upon entering into the server or being displayed on the log viewer page, this allows for an XSS or XSRF injection point.<\/p>\n<h3>110<\/h3>\n<p>By removing the \u201ctopic\u201d URL variable, an un-handled exception is thrown.&nbsp; The result of this NullPointerException is the displaying of a small portion of the relevant page code via a standard Tomcat 500 Error page.&nbsp; The benefit of the displayed code is to learn the input filtering code to more easily find a way to evade it.&nbsp; This should be used in conjunction with Goals 111 and 112.<\/p>\n<h3>111<\/h3>\n<p>The \u201ctopic\u201d URL variable\u2019s value is filtered to replace any instance of \u201c..\/\u201d with a blank string to prevent directory traversal.&nbsp; Because this process is not recursive, by using \u201c\u2026.\/\/\u201d the filter will remove the inner-most \u201c..\/\u201d and leave the remaining \u201c..\/\u201d intact.&nbsp; This should be used in conjunction with Goal 112.<\/p>\n<h3>112<\/h3>\n<p>The \u201ctopic\u201d URL variable\u2019s value is appended with \u201c.html\u201d.&nbsp; By placing a question mark at the end of the original variable\u2019s value, the appended \u201c.html\u201d appears to be part of the query portion of the included URL (e.g. \u201cindex.jsp?\u201d becomes \u201cindex.jsp?.html\u201d).<\/p>\n<h3>113<\/h3>\n<p>By instructing the FAQ page to include itself, an infinite loop occurs as the server tries to continuously nest pages.&nbsp; This causes a denial of service and with multiple threads started on this process, the server will crash quickly.<\/p>\n<h3>120<\/h3>\n<p>The \u201cusers\u201d table in the MySQL database stores the secret (mother\u2019s maiden name) in Base64 format.&nbsp; This is used to verify that the forgotten password restoration request is coming from the account owner.&nbsp; Because Base64 is just an encoding method and not encryption or hashing, any user with access to the MySQL database can decode the secrets easily and are able to reset the password and have the new one sent to the owner\u2019s e-mail.&nbsp; This alone will not allow access to the account since contestants do not have access to the account owners\u2019 e-mail inboxes.<\/p>\n<h3>200<\/h3>\n<p>By modifying the \u201cid\u201d variable when attempting to edit a comment for a transaction, a user is able to post the comment for any transaction.&nbsp; Essentially, the \u201cid\u201d variable is not checked to verify that the user actually owns the transaction it is associated with.<\/p>\n<h3>201<\/h3>\n<p>The transaction comments are neither filtered nor encoded upon entering into the server or being displayed on the transaction page.&nbsp; This allows for an easy XSS or XSRF injection point.<\/p>\n<h3>300<\/h3>\n<p>The only method of initially gaining access to the \/secure\/siteadmin\/ area of the site is by logging-in through the \/secure\/login.jsp with correct site admin credentials.&nbsp; In order to do this, one needs the username and password.&nbsp; The username is easily obtainable after the contestant has gain access to the MySQL database, but the password hash must be cracked.&nbsp; The contestant must run the password hashes through a password cracking tool or an online rainbow table.<\/p>\n<h3>310<\/h3>\n<p>The active_users.jsp page shows a list of all sessions active, including username, e-mail address, role, and last activity time.&nbsp; Session IDs are shown as well, but our censored for contestants to prevent cross-contestant hacking and cheating.&nbsp; One user \u201crscott\u201d, a financial manager, is hard-coded to always have an active session.&nbsp; By modifying their session cookie to the session ID listed for rscott, contestants can gain access to the financial manager\u2019s already logged-in account.<\/p>\n<h3>400<\/h3>\n<p>There is technically no vulnerability on this page, but in order to successfully transfer funds, the manager account\u2019s password must be re-entered and thus known by the contestant.&nbsp; To gather this information, contestants must first gain access to the manager\u2019s account using Goal 310, change the e-mail address to their own, log out, and then use the \u201cforgot my password\u201d feature (Goal 120).<\/p>\n<h1><\/h1>\n<h1>Walkthrough<\/h1>\n<h2>Forward<\/h2>\n<p>This guide assumes that you are using the SecurityFirst distributed VM and have made no modifications to any part of the system.&nbsp; This includes web applications, databases, and client configurations.&nbsp; Because the scores and database system are persistent through reboot, it is preferable to make a \u201cclean\u201d copy or snapshot of the VM before beginning to work on the exercises.<\/p>\n<p>To get started, log into the operating system with the username \u201chacker\u201d and password \u201c1234\u201d.&nbsp; Once logged in, open Firefox and navigate to the SecurityFirst website using the provided bookmark.&nbsp; If prompted, enter your name to track your score.<\/p>\n<h2>Section 1: &nbsp;Gaining Access to the Database<\/h2>\n<h3>Goal 100: &nbsp;Source Code Disclosure #1<\/h3>\n<ol>\n<li>Log out if you are already logged in as a user.<\/li>\n<li>Navigate to either \u2018\/site\/index.jsp\u2019 or \u2018\/site\/login.jsp\u2019.<\/li>\n<li>Open the Tamper Data extension for Firefox and click \u2018Start Tamper\u2019.<\/li>\n<li>In the login form on the page, type a few letters or numbers into both the username and password field and click \u2018Submit\u2019.<\/li>\n<li>Tamper Data should pop up and ask you what action you would like to take. Uncheck \u2018Continue Tampering\u2019 and click the button label \u2018Tamper\u2019.<\/li>\n<li>On the right side of the following window, right-click on the either username or password and select \u2018Delete Element\u2019.<\/li>\n<li>Click the \u2018Ok\u2019 button at the bottom of the window to submit the tampered request. This should display a Tomcat error page with a portion of the JSP page\u2019s code shown.<\/li>\n<li>Note the include statement for file \u201cincludes\/database_info.jspf\u201d.<\/li>\n<\/ol>\n<h3>Goal 110: &nbsp;Source Code Disclosure #2<\/h3>\n<ol>\n<li>Navigate to \u2018\/site\/faq.jsp\u2019 by clicking the \u201cFrequently Asked Questions\u201d link on the left side of the page.<\/li>\n<li>Modify the URL in the address bar so there is no longer a parameter named \u201ctopic\u201d.<\/li>\n<li>Press Enter after modifying the URL to request the new page. &nbsp;This should display a Tomcat error page with a portion of the JSP page\u2019s code shown.<\/li>\n<li>Note the String replace function that removes any occurrence of \u201c..\/\u201d from the \u201ctopic\u201d parameter.<\/li>\n<\/ol>\n<h3>Goal 111 and 112:&nbsp; Local File Inclusion via Filter Evasion<\/h3>\n<ol>\n<li>Navigate to \u2018\/site\/faq.jsp\u2019 by clicking the \u201cFrequently Asked Questions\u201d link on the left side of the page.<\/li>\n<li>Modify the URL in the address bar so the \u201ctopic\u201d parameter is set to: \u2026.\/\/index.jsp. The URL should be: jsp?topic=\u2026.\/\/index.jsp<\/li>\n<li>Press Enter after modifying the URL to request the new page. &nbsp;This should display an error message stating that \u201c\/site\/index.jsp.html\u201d could not be found.<\/li>\n<li>Modify the URL in the address bar so the \u201ctopic\u201d parameter is set to: \u2026.\/\/index.jsp?. The URL should be: jsp?topic=\u2026.\/\/index.jsp?<\/li>\n<li>Press Enter after modifying the URL to request the new page. This should display the index page nested inside of the FAQ page.<\/li>\n<\/ol>\n<h3>Putting It All Together<\/h3>\n<ol>\n<li>Navigate to \u2018\/site\/faq.jsp\u2019 by clicking the \u201cFrequently Asked Questions\u201d link on the left side of the page.<\/li>\n<li>Modify the URL in the address bar so the \u201ctopic\u201d parameter is set to: \u2026.\/\/includes\/database_info.jspf?<\/li>\n<li>Press Enter after modifying the URL to request the new page. This should display the contents of the database include file.<\/li>\n<li>Note the database username and password.<\/li>\n<li>Using the Firefox bookmark, navigate to phpMyAdmin (http:\/\/securityfirst.com\/phpmyadmin\/)<\/li>\n<li>Log in with the username and password you just discovered.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<h2>Section 2: &nbsp;Logging In As a Customer<\/h2>\n<h3>Goal 101: &nbsp;SQL Injection<\/h3>\n<ol>\n<li>Log out if you are already logged in as a user.<\/li>\n<li>Navigate to either \u2018\/site\/index.jsp\u2019 or \u2018\/site\/login.jsp\u2019.<\/li>\n<li>Open the Tamper Data extension for Firefox and click \u2018Start Tamper\u2019.<\/li>\n<li>In the login form on the page, type a few letters or numbers into both the username and password field and click \u2018Submit\u2019.<\/li>\n<li>Tamper Data should pop up and ask you what action you would like to take. Uncheck \u2018Continue Tampering\u2019 and click the button label \u2018Tamper\u2019.<\/li>\n<li>On the right side of the following window, change the contents of the \u2018password\u2019 textbox from the MD5 hash to the following: \u2018 OR \u2018a\u2019=\u2019a<\/li>\n<li>Click the \u2018Ok\u2019 button at the bottom of the window to submit the tampered request. This should log you into the first user in the database, Thomas Dunlin.<\/li>\n<\/ol>\n<h3>Goal 102: &nbsp;MD5 Hash Replay<\/h3>\n<ol>\n<li>Log in to phpMyAdmin using the method at the end of Section 1.<\/li>\n<li>On the left menu, choose the SecurityFirst database, followed by the \u2018users\u2019 table.<\/li>\n<li>Select \u201cBrowse\u201d from the list of tabs at the top of the page.<\/li>\n<li>Note the list of users displayed below, along with their password hashes and other information. Pick one of the users with a \u201crole\u201d of 0, and copy their password hash to your clipboard.<\/li>\n<li>Return to the SecurityFirst web application or open it in a new window or tab.<\/li>\n<li>Log out if you are already logged in as a user.<\/li>\n<li>Navigate to either \u2018\/site\/index.jsp\u2019 or \u2018\/site\/login.jsp\u2019.<\/li>\n<li>Open the Tamper Data extension for Firefox and click \u2018Start Tamper\u2019.<\/li>\n<li>In the login form on the page, type a few letters or numbers into both the username and password field and click \u2018Submit\u2019.<\/li>\n<li>Tamper Data should pop up and ask you what action you would like to take. Uncheck \u2018Continue Tampering\u2019 and click the button label \u2018Tamper\u2019.<\/li>\n<li>On the right side of the following window, change the contents of the \u2018username\u2019 textbox to the username of the chosen user account from the MySQL database in step 4. Also change the \u2018password\u2019 textbox to the password hash of the chosen user account.&nbsp; If you copied this data to your clipboard you can simply paste it.<\/li>\n<li>Click the \u2018Ok\u2019 button at the bottom of the window to submit the tampered request. This should log you into the customer account you chose.<\/li>\n<\/ol>\n<h2>Section 3: &nbsp;Stealing the Money<\/h2>\n<h3>Goal 300:&nbsp; Weak Password Hash Cracking<\/h3>\n<ol>\n<li>Log in to phpMyAdmin using the method at the end of Section 1.<\/li>\n<li>On the left menu, choose the SecurityFirst database, followed by the users table.<\/li>\n<li>Select \u201cBrowse\u201d from the list of tabs at the top of the page.<\/li>\n<li>Note the list of users displayed below, along with their password hashes and other information. Copy the password hash of \u201cFrank Smith\u201d to your clipboard.<\/li>\n<li>Open a terminal and type the following (replace &lt;hash&gt; with the hash in your clipboard by right-clicking on the window and pasting): md5crack a 1 3 &lt;hash&gt;<\/li>\n<li>Press enter to begin the cracking process.<\/li>\n<li>When the password is found, go back to the SecurityFirst login page and log out if needed. Login as \u201cfsmith\u201d using the password.&nbsp; After you are redirected to the secure page, do the same again.<\/li>\n<\/ol>\n<h3>Goal 310:&nbsp; Session Hijacking<\/h3>\n<ol>\n<li>Navigate to \u2018\/secure\/siteadmin\/active_users.jsp\u2019 by clicking the \u201cSite Administrative Panel\u201d button at the bottom-right of the page, followed by the \u201cActive Sessions\u201d link.<\/li>\n<li>Copy the Session ID of \u201crscott\u201d to the clipboard.<\/li>\n<li>On the Firefox toolbar, select Tools, followed by Cookie Editor.<\/li>\n<li>Find and select the JSESSIONID cookie for the host \u201csecurityfirst.com\u201d. Click the \u201cEdit\u201d button to modify the cookie.<\/li>\n<li>Remove the contents of the \u201cContent\u201d text box and paste the Session ID you copied into the box. Click \u201cSave\u201d.<\/li>\n<li>Close the Cookie Editor window.<\/li>\n<li>Refresh the current page or navigate to another.<\/li>\n<li>Note that you are now user \u201crscott\u201d.<\/li>\n<\/ol>\n<h3>Goal 120:&nbsp; Insecure Cryptographic Storage<\/h3>\n<ol>\n<li>As user \u201crscott\u201d, click \u201cChange E-mail Address\u201d on the right-side menu.<\/li>\n<li>Enter \u201chacker@hacker.com\u201d. Click \u201cSubmit\u201d to change the email address.<\/li>\n<li>Click the \u201cLogout\u201d button on the right-side menu.<\/li>\n<li>Log in to phpMyAdmin using the method at the end of Section 1.<\/li>\n<li>On the left menu, choose the SecurityFirst database, followed by the users table.<\/li>\n<li>Select \u201cBrowse\u201d from the list of tabs at the top of the page.<\/li>\n<li>Note the list of users displayed below, along with their password hashes and other information. Copy the Base64 encoded secret of \u201cRoger Scott\u201d to your clipboard.<\/li>\n<li>Press F9 on your keyboard to open the HackBar extention in Firefox. Click the \u201cEncoding\u201d menu button, followed by the \u201cBase64 Decode\u201d item.<\/li>\n<li>In the window that appears, remove \u201cString to use\u201d from the textbox and paste the Base64 encoded secret you copied previously. Click the \u201cOk\u201d button.<\/li>\n<li>The resulting string is placed in the HackBar textarea. Select and copy it to the clipboard.<\/li>\n<\/ol>\n<h3>Goal 400:&nbsp; Weak Password Management Policy<\/h3>\n<ol>\n<li>Return to the SecurityFirst web application and navigate to \u2018\/site\/index.jsp\u2019. Ensure you are logged out.<\/li>\n<li>Under the login form on the right-hand side of the page, click the \u201chere\u201d link.<\/li>\n<li>In the form provided, enter \u201crscott\u201d in the username textbox and paste the decoded secret into the \u201cMother\u2019s maiden name\u201d textbox.<\/li>\n<li>Click \u201cSubmit\u201d. A message should appear, informing you that a password reset mail has been sent to the account owner\u2019s e-mail address.<\/li>\n<li>Using the Firefox bookmark, navigate to SquirrelMail (http:\/\/hacker.com\/mail\/)<\/li>\n<li>Login as \u201chacker\u201d as the username and \u201c1234\u201d as the password.<\/li>\n<li>Navigate to either \u2018\/site\/index.jsp\u2019 or \u2018\/site\/login.jsp\u2019. Enter the username as \u201crscott\u201d and paste the password you received into the password textbox.&nbsp; After you are redirected to the secure page, do the same again.<\/li>\n<li>Navigate to \u2018\/secure\/financial_manager\/transfer_funds.jsp\u2019 by clicking the \u201cFinancial Manager\u2019s Panel\u201d button at the bottom-right of the page, followed by the \u201cTransfer Funds\u201d link.<\/li>\n<li>Enter \u201c109762820\u201d and \u201c110806729\u201d into the source account and destination account textboxes respectively. Enter any positive number into amount textbox, 500.00 for example.&nbsp; Paste the password for \u201crscott\u201d into the password box.&nbsp; Click the \u201cSubmit\u201d button to transfer the funds.<\/li>\n<\/ol>\n<h2>Section 4:&nbsp; Leaving a Mark<\/h2>\n<h3>Goal 201:&nbsp; Cross-Site Scripting<\/h3>\n<ol>\n<li>Log in as a customer-role user using a method from Section 2.<\/li>\n<li>Navigate to \u2018\/customer\/editcomment.jsp\u2019 by clicking the \u2018View Recent Transactions\u2019 button, followed by the \u2018details\u2019 link for one of the transactions, and finally the \u2018edit comment\u2019 link.<\/li>\n<li>In the textbox on the page, enter &lt;script&gt;alert(\u201chi\u201d)&lt;\/script&gt; and click \u2018Submit\u2019.<\/li>\n<li>When the transaction page loads, you should see an alert box appear.<\/li>\n<\/ol>\n<h3>Goal 200:&nbsp; Request Variable Manipulation<\/h3>\n<ol>\n<li>Log in as a customer-role user using a method from Section 2.<\/li>\n<li>Navigate to \u2018\/customer\/editcomment.jsp\u2019 by clicking the \u2018View Transactions\u2019 button, followed by the \u2018details\u2019 link for one of the transactions, and finally the \u2018edit comment\u2019 link.<\/li>\n<li>On the very bottom-right edge of the Firefox window, click the icon that resembles a bug to open the FireBug pane.<\/li>\n<li>Click the \u201cInspect\u201d button at the top of theFireBug pane. With the Inspecting option toggled on, click the comment textbox on the page.<\/li>\n<li>Find the following line in the FireBug pane (the number may be different).<br \/> &lt;form method=\u201dpost\u201d action=\u201d?id=1\u201d&gt;<\/li>\n<li>Click on the \u201c?id=1\u201d portion of the textarea. In the mini-textbox that opens, change the number to another number (higher than 4).&nbsp; Press \u201cEnter\u201d to close the mini-textbox.<\/li>\n<li>Click the FireBug icon on the bottom-right of Firefox to close the window pane.<\/li>\n<li>Click the \u201cSubmit\u201d button on the page.<\/li>\n<\/ol>\n<h3>Goal 103:&nbsp; Log Poisoning<\/h3>\n<ol>\n<li>Log out if you are already logged in as a user.<\/li>\n<li>Navigate to either \u2018\/site\/index.jsp\u2019 or \u2018\/site\/login.jsp\u2019.<\/li>\n<li>In the login form on the page, enter &lt;script&gt;alert(\u201chi\u201d)&lt;\/script&gt; into the username field and click \u2018Submit\u2019.<\/li>\n<li>Click the \u2018Ok\u2019 button at the bottom of the window to submit the tampered request.<\/li>\n<li>If this is your first time scoring this goal, enter \u2018\/secure\/siteadmin\/logviewer.jsp\u2019 (no quotes) in the goal score page to answer the question correctly. Submit the form.<\/li>\n<li>Log in as a siteadmin-role user using the password discovered for Goal 300 in Section 3.<\/li>\n<li>Navigate to \u2018\/secure\/siteadmin\/logviewer.jsp\u2019.<\/li>\n<li>When the transaction page loads, you should see an alert box appear.<\/li>\n<\/ol>\n<h3>Goal 113:&nbsp; Crashing the Web Server<\/h3>\n<ol>\n<li>Navigate to \u2018\/site\/faq.jsp\u2019 by clicking the \u201cFrequently Asked Questions\u201d link on the left side of the page.<\/li>\n<li>Modify the URL in the address bar so the \u201ctopic\u201d parameter is set to: \u2026.\/\/faq.jsp? The URL should be: jsp?topic=\u2026.\/\/faq.jsp?<\/li>\n<li>Press Enter after modifying the URL to request the new page. This should display three nested FAQ pages.<\/li>\n<li>Note if this was unchecked, the server would continue processing this until it ran out of memory and crashed.<\/li>\n<\/ol>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>SecurityFirst Competition v2.1 Competition Information. 1 Background. 1 Objectives. 1 Rules. 2 Reference. 3 Users. 3 Goals. 3 Walkthrough. 6 Forward. 6 Section 1:&nbsp; Gaining Access to the Database. 6 Section 2:&nbsp; Logging In As a Customer. 7 Section 3:&nbsp; <a href=\"https:\/\/www.benedictsol.com\/blogs\/describe-all-14-vulnerabilities-exposed-in-the-security-first-lab-in-layman-terms-and-explain-why-each-step-is-important-without-using-the-objective-listed\/\" class=\"read-more\">Read More &#8230;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-35235","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/posts\/35235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/comments?post=35235"}],"version-history":[{"count":0,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/posts\/35235\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/media?parent=35235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/categories?post=35235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.benedictsol.com\/blogs\/wp-json\/wp\/v2\/tags?post=35235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}