> For the complete documentation index, see [llms.txt](https://thamizhiniyancs.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://thamizhiniyancs.gitbook.io/writeups/hackthebox/tracks/beginner-track/you-know-0xdiablos.md).

# You Know 0xDiablos

You Know 0xDiablos writeup by Thamizhiniyan C S

## Overview

Hello everyone, In this writeup we are going to solve You Know 0xDiablos from HackTheBox.

Link for the machine : <https://app.hackthebox.com/challenges/106>

Lets Start 🙌

***

## Initial Setup

First download the given file.

The give file is a zip file. Extract the zip file using the following command and the given password:

Command: `7z <zip_file>`

{% hint style="info" %}
Check this to install `7z`:

<https://www.digitalocean.com/community/tutorials/install-7zip-ubuntu>
{% endhint %}

password: `hackthebox`

We have got a file name `vuln` in the zip. I tried the `file` command on the `vuln` file to identify its type.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FS89qFFjCfy2lwd8zoSRk%2FUntitled.png?alt=media&amp;token=22f5a06c-34c6-4ddf-a5e0-05336d4abe35" alt=""><figcaption></figcaption></figure>

It is an ELF executable file.

***

## Application Interaction

Next I ran the Executable. First give the `vuln` file executable permissions using the command `chmod +x vuln` and then run the file.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FlVmQcpQUSTMp5Q941Sdo%2FUntitled%201.png?alt=media&amp;token=ed58e779-54a2-4969-89f8-bd4d68ce0ab0" alt=""><figcaption></figcaption></figure>

The executable is asking for some string, which we have to find to get the flag.

***

## Enumeration

### Strings

I tried `strings` on the `vuln` file.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FsTJY3LZvCrZnpihR9n7c%2FUntitled%202.png?alt=media&amp;token=b2a268c7-8b80-4bfa-b218-76b5d197ef8b" alt=""><figcaption></figcaption></figure>

And found a file named `flag.txt` , which we will get access if we enter the correct string.

Next I opened the executable in `Ghidra`.

### Ghidra

I found the following functions under the functions drop down in symbol tree tab.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2Fbsb3fUdHBXUuBMvqIO34%2FUntitled%203.png?alt=media&amp;token=a27c88fa-f361-4734-bb94-0fd054be9665" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
If you weren’t able to locate the functions drop down, do this to see a list of all the functions: Go to the Windows menu in the tool bar and press Functions. You will see a tab opened like this:

<img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FGjRUilk1rlcoMUQG2OVk%2FUntitled%204.png?alt=media&amp;token=50e1325d-cbc4-42ec-94c3-131dcbb45aa3" alt="" data-size="original">
{% endhint %}

I first took a look at the main function. To view the decompiled version of the main function, double click on the function name in the Functions tab and then switch to the `Decompile` tab.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FhaqfYpmbUvylX00Rudrn%2FUntitled%205.png?alt=media&amp;token=2044fec3-0824-40aa-8a56-a3ab700def1b" alt=""><figcaption></figcaption></figure>

The main function prints out the string “`You know who are 0xDiablos:` ” and it calls another function `vuln()`.

### Identifying the Vulnerability

Now to take a look at the `vuln()` function, double click on it. You can now see the `vuln` function displayed.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FfnFywmK82VEhmPbCRdRr%2FUntitled%206.png?alt=media&amp;token=242b8120-a289-4d2b-ae94-8afdf168f576" alt=""><figcaption></figcaption></figure>

The `vuln` function first declares a variable `local_bc` of type `char` and of size 180 bytes. Next it gets the input from the user and stores it in the `local_bc` variable using the `gets()` method and it also prints out the `local_bc` variable using `puts()` method.

The `local_bc` is the place where the string that we give as a input in the program stores and printed out.

The `vuln()` function uses the `gets()`method to get the input. The `gets()` method is vulnerable to buffer overflow attack, as it doesn’t take in a size argument i.e., the `gets()` method doesn’t has a limit size for the input, which on getting a input of larger size than the size of the variable to which the value is stored, in this case the `local_bc` variable with a size (aka buffer) of 180 bytes, the program will crash and throws an segmentation fault error. This is know as a buffer overflow attack.

***

## Testing the Vulnerability

Let’s try to simulate the above mentioned attack process. First I tried by giving an input of 180 characters. It worked flawlessly with no errors:

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2Fz5QYmkHilkD9Q7nyinpU%2FUntitled%207.png?alt=media&amp;token=30af61a3-5150-48ff-9866-1cdb68b6314f" alt=""><figcaption></figcaption></figure>

Next I tried by giving an input of 200 characters, which is more than the size of the variable `local_bc`.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FxeIoNLdfLpcwDS3IzuG9%2FUntitled%208.png?alt=media&amp;token=9ca502fc-c259-4ee3-b25b-5a8e07ed3a91" alt=""><figcaption></figcaption></figure>

We can see that the program throws a segmentation fault error.

Now we have made the buffer / size of the variable overflowing with excess data. Next we have to exploit this vulnerability to make the program to do what we want.

Before diving deeper, let’s also take a look at the `flag` function, which is not called at all in any of the above functions that we saw.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FXQhIdAHBwiS70QHEsMCu%2FUntitled%209.png?alt=media&amp;token=79b91ce7-c9a5-44d7-9564-99926886f6e8" alt=""><figcaption></figcaption></figure>

The flag function gets two parameters. This function on called, opens the flag.txt and prints out the flag to the screen if the parameters match the conditions.

So, our task is to perform the buffer overflow attack and call this `flag()` function to get the flag.

***

## Exploitation - The Attack in Detail

Let’s use a debugger to exploit the buffer overflow. In my case I use the `gdb` debugger with `gef` extension. You can use your own favourite debugger.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FVVRP2hrKoXTZA4dKH21i%2FUntitled%2010.png?alt=media&amp;token=4b6f2345-b673-4b80-9cb2-1d2fb177ed4a" alt=""><figcaption></figcaption></figure>

### Disassembling the Main Function

First we can disassemble the main function.

Command: `disas main`

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2Fl7XF99gkDQbgNwHwSSW7%2FUntitled%2011.png?alt=media&amp;token=7e645c80-39f1-4278-9116-541cd46bc2b7" alt=""><figcaption></figcaption></figure>

In the main function you can see the call for the `vuln` function. The `vuln` function has a memory address of `0x8049070`.

### Disassembling the Vuln Function

Next we can disassemble the `vuln` function.

Command: `disas vuln`

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2F35vrsv4zJ8Uhl1vvwV70%2FUntitled%2012.png?alt=media&amp;token=c51485df-866c-48b0-b9b9-337df8ad3103" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Check these to know about the assembly instructions:&#x20;

* <https://cheatography.com/siniansung/cheat-sheets/linux-assembler/>
* &#x20;<https://trailofbits.github.io/ctf/vulnerabilities/references/X86_Win32_Reverse_Engineering_Cheat_Sheet.pdf>
* <https://www.cs.virginia.edu/~evans/cs216/guides/x86.html>
  {% endhint %}

In the above screenshot, we can see the `vuln` function in assembly language. You can see the declaration of the variable and getting and printing the variable lines.

Detailed breakdown of the variable declaration line:

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FE1K1keDU9UFdXNA0PEUO%2FUntitled%2013.png?alt=media&amp;token=d81614ea-4227-44a4-ab4d-61900ee93f8a" alt=""><figcaption></figcaption></figure>

The size of the variable is in hexadecimal format. To view it in decimal format, print it using python.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2Ft2033DWB5czI9TNFw3cu%2FUntitled%2014.png?alt=media&amp;token=1d5ead23-1c01-4122-9dd5-00ee6dd6a4ef" alt=""><figcaption></figcaption></figure>

You may notice that the size of the variable is `184`, whereas in the program, the size of the declared variable was `180`. It is possible for some extra bits to be allocated during memory allocation, and this is a common behaviour.

Now we can try to give excess data as input and run the program in the decompiler.

Command: `run < <(python3 -c 'print("A" * 200)')`

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FBA3NbwhVNamTQxVBJoiG%2FUntitled%2015.png?alt=media&amp;token=26d0ab19-ee8e-4beb-a1f9-adc1408bf3ac" alt=""><figcaption></figcaption></figure>

You can see the segmentation error.

You can see the Instruction Pointer ( `eip` ) is overwritten by `0x41414141` , which is the hexadecimal version of string “AAAA”. Instead of these A’s, we have to replace the Instruction pointers value to the memory address of the function `flag()`, so that we could retrieve the flag.

To overwrite the Instruction Pointer, we first need to find the offset. This means we need to determine the number of characters after the first 180 characters that will overwrite the Instruction Pointer.

To accomplish this, we can manually add characters one by one, run the program, and determine the character count at which the instruction pointer is overwritten.

### Finding the Offset

First, we can add `4` characters additional to the `180` characters, a total of `184` characters and check the Instruction Pointer.

Command: `run < <(python3 -c 'print("A" * 180) + "BBBB"')`

Here I have concatenated “BBBB” to the input string after A’s for easy identification of the position. You can use any characters.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2F1SMt0zvzmtk04S62Px72%2FUntitled%2016.png?alt=media&amp;token=acf0275d-58c5-44a1-a1fe-a1f9c002d070" alt=""><figcaption></figcaption></figure>

You can see that the Instruction Pointer is not yet overwritten.

Now we can add 4 more characters, total of `188` characters and run the program.

Command: `run < <(python3 -c 'print("A" * 180) + "BBBB" + "CCCC"')`

Here I have concatenated “BBBB” and “CCCC” to the input string after A’s for easy identification of the position. You can use any characters.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FbYLGUnuBpZKPdEWiprEB%2FUntitled%2017.png?alt=media&amp;token=7f25f279-62e4-4e05-b60f-8e72416ada0e" alt=""><figcaption></figcaption></figure>

This time also the Instruction Pointer is not overwritten, but we can see that the Base and Base Pointer is overwritten by characters that we have entered.

Let’s try again by adding 4 more characters, a total of 192 characters and run the program.

Command: `run < <(python3 -c 'print("A" * 180) + "BBBB" + "CCCC" + "DDDD"')`

Here I have concatenated “BBBB” ,“CCCC” and “DDDD” to the input string after A’s for easy identification of the position. You can use any characters.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FnUJVqcB9yHaYeIxz4XLL%2FUntitled%2018.png?alt=media&amp;token=ddee734a-8bcc-4343-b754-c261a945dfa8" alt=""><figcaption></figcaption></figure>

This time, we got the Instruction Pointer overwritten by the characters “DDDD”. This shows that, after `188` characters, the Instruction Pointer can be overwritten. So the Offset is `188` characters.

***

## Getting the Flag

We have successfully found the offset. Next we have to find the memory address of the `flag` function. To get the address, first we have to disassemble the flag function. The first line of the output is the address of the `flag()` function.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2Ftva6qljJspctCjfLHMJt%2FUntitled%2019.png?alt=media&amp;token=76b72ce8-4adf-4989-9fa1-086a725dd5b5" alt=""><figcaption></figcaption></figure>

To satisfy the condition and obtain the flag, the address of the parameter values in the flag function must be passed along with the function.

You can find the address of the values by double pressing the value in ghidra. You can also see the address of the values in the disassembled version of flag function.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FWieVSXPIlosQX7lzqvW2%2FUntitled%2020.png?alt=media&amp;token=a5927183-fb6b-48d0-a366-d99a8e611257" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2Fb8Z8ryzT3tbwrOXGm5qz%2FUntitled%2021.png?alt=media&amp;token=ce752249-8cde-4bfa-9c87-fc5e7fe7bd40" alt=""><figcaption></figcaption></figure>

So we have got all the necessary details to generate a input that overwrites the Instruction Pointer with the call for the `flag()` function. Now we can construct the input:

{% hint style="info" %}
Note: We have to provide the memory address values in the input in [Little-Endian Format](https://www.section.io/engineering-education/what-is-little-endian-and-big-endian/#:~:text=Specifically%2C%20little%2Dendian%20is%20when,first%20\(the%2012%20part\).)
{% endhint %}

| Name/Function | Memory Address | Little Endian Fromat |
| ------------- | -------------- | -------------------- |
| flag()        | 0x080491e2     | \xe2\x91\x04\x08     |
| param1        | 0xdeadbeef     | \xef\xbe\xad\xde     |
| param2        | 0xc0ded00d     | \x0d\xd0\xde\xc0     |

```bash
python3 -c "import sys; sys.stdout.buffer.write(b'A'*188+b'\xe2\x91\x04\x08' + b'PADD' + b'\xef\xbe\xad\xde\x0d\xd0\xde\xc0')"
// Here I have used sys.stdout.buffer.write instead of print because 
// we are giving the input in bytes.
// Here I have used b'PADD' to add padding. Make sure to add this
// \x is used to mention that it is hexadecimal
```

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FaoQYnlqSZDoGLjnKMuNm%2FUntitled%2022.png?alt=media&amp;token=e2eddce3-872f-4f5e-bd73-cea51eddb55a" alt=""><figcaption></figcaption></figure>

We can see that the input that we created is successfully working.

Now save the generated input in a text file.

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FCHxCYLe274lpyiTY6ayx%2FUntitled%2023.png?alt=media&amp;token=8f7146f8-f5d4-47a7-8b95-a2d6fefb71e3" alt=""><figcaption></figcaption></figure>

We can test the generated text file by the following command:

```bash
cat input.txt - | ./vuln
// Here we are using '-' to pass the input value once we press the enter
// Run the above command and don't forget to press enter
```

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2FhHsNWJbuOd9sRYrfG7w1%2FUntitled%2024.png?alt=media&amp;token=90a37cc2-151b-4078-82e6-aa1500014516" alt=""><figcaption></figcaption></figure>

We have successfully performed the buffer overflow attack and called the `flag()` function.

Now start the machine and try the input in the target web server using `netcat` , using the above method : `cat input.txt - | nc 167.172.61.89 30939`

<figure><img src="https://3766366075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmgBRtrRN7KBbA6FISaV1%2Fuploads%2F7qf7yRJ6MSqacqySis4O%2FUntitled%2025.png?alt=media&amp;token=6cd7c4f0-598e-445a-a016-abbceda4f78c" alt=""><figcaption></figcaption></figure>

We have successfully got the flag……

Thank You!!!!
