Hackfest 2016: Sedna

This is another machine in the Hackfest 2016 series.

There are 4 flags on this machine One for a shell One for root access Two for doing post exploitation on Sedna

Alrighty, let’s hack the planet!

Take the SpyderSec Challenge

The challenge:

You are looking for two flags. Using discovered pointers in various elements of the running web application you can deduce the first flag (a downloadable file) which is required to find the second flag (a text file). Look, read and maybe even listen. You will need to use basic web application recon skills as well as some forensics to find both flags.

Git me some Irn-Bru ye Teuchter!

Today’s target is called Teuchter, and yes, apparently that’s a word. There is a theme for this machine, and this why this blog post is also..different. ye will need to hang tight to yer sanity for this one. Or drink some Irn-Bru. Ah had to look at other walkthroughs when Ah got stuck and some time was spent checking Scottish references, but it was all worth it!

So, what’s a Teuchter? The Wiktionary definition is:

(derogatory) A Highlander especially if Gaelic-speaking; a rural Scot in general; (in Glasgow and surrounding areas) a Scot with a thick accent from outside west-central Scotland.

Some hints from the author:

This VM is designed to be a bit of a joke/troll so a translator might be useful.

The challenge isn’t over with root. I’ve done my usual flag shenanigans.

A bit of info security research and knowing yer target helps here.

And this one:

Less hochmagandy and more studying is needed for this one!

Ah am sure ye have questions, so:

hochmagandy – Scottish a mainly jocular or literary word for sexual intercourse

Isn’t this a promising start..

Hack the IMF

The VM description states that IMF is a intelligence agency that you must hack to get all flags and ultimately root. The flags start off easy and get harder as you progress. Each flag contains a hint to the next flag.

The difficulty is Beginner/Moderate