๐Advent of Cyber 4 (2022)
Get started with Cyber Security in 24 Days - learn the basics by doing a new, beginner-friendly security challenge every day leading up to Christmas.
Last updated
Get started with Cyber Security in 24 Days - learn the basics by doing a new, beginner-friendly security challenge every day leading up to Christmas.
Last updated
Room Attributes | Value |
---|---|
Your task is to help the Elves solve a puzzle left for them to identify who is trying to stop Christmas. Click the View Site button at the top of the task to launch the static site in split view. You may have to open the static site on a new window and zoom in for a clearer view of the puzzle pieces.
Once you complete the puzzles you'll be presented with defaced site containing the flag and a calling card from the malicious actor:
No answer needed
No answer needed
ls
command to list the files present in the current directory. How many log files are present?HINT: The directory needs to be /home/elfmcblue
. You can use cd
to change to this cd /home/elfmcblue
HINT: You can use the ls
command to list the files present in the directory.
No answer needed
HINT: This answer is looking for a day in the week.
HINT: The attacker only made one request to the web server.
HINT: Using grep recursively allows you to quickly look through a bunch of log files for a value.
No answer needed
santagift.shop
?HINT: Check the who.is/whois website to find WHOIS information.
All the information you need can be found on https://who.is/whois/santagift.shop
HINT: Use the same search terms that Recon McRed used on github.com to find the leaked source code.
All the information you need can be found on https://github.com/muhammadthm/SantaGiftShop
HINT: Check the file containing sensitive credentials.
config.php contains several secrets in code that are publicly readable in source code:
No answer needed
HINT: Try nmap -sV MACHINE_IP in the AttackBox.
HINT: It is located in the admins folder.
No answer needed
The Bandit Yeti
THM{IT'S A Y3T1 CHR1$TMA$}
2
webserver.log
Friday
10.10.249.191
santaslist.txt
THM{STOLENSANTASLIST}
NAMECHEAP INC
{THM_OSINT_WORKS}
config.php
qa.santagift.shop
S@nta2022
Apache
ssh
{THM_SANTA_SMB_SERVER}
santa25
Subscription Required
False [Free]
Type
Walkthroughs
Difficulty
Easy
Tags
beginner, christmas, challenge, advent