Jump to content


Active Members
  • Posts

  • Joined

  • Last visited

  • Days Won


Profile Information

  • Gender
  • Location
    The Untidied Kingdoms
  • Interests
    Electro Magnetism
    Emergent Phenomena
    Cognitive Dissonance
    Acoustic Guitar
    Coke Zero
    & Tropical Fruits

Recent Profile Visitors

2,893 profile views

3mrgnc3's Achievements


Newbie (1/14)

  1. Afaik, devices call back via auto ssh on port 2022. the web interface is just for you to control everything. I too have a problem with a similar config though, but with my TETRA. I am also using c2 behind an NGINX reverse proxy with HTTPS. For me The TETRA connects back fine (via ssh), but Terminal wont work properly. When i select it I just get a double disconnected error message in the window. Disconnected. Disconnected. And on my VPS I get the following error message. [*] Initializing Hak5 Cloud C2 [*] Running Hak5 Cloud C2 2018/12/24 12:40:02 http: multiple response.WriteHeader calls I suspect this is being caused by my reverse_proxy configuration. I think I should be able to solve it with the correct nginx directive to tell the webserver to correctly handle the asynchronous terminal stuff? I haven't for the life of me been able to solve it yet though. If anyone has any suggestions, I'd be very grateful. EDIT... This is my nginx sites-available file for the domain I'm using server { ssl_certificate /opt/C2C/certs/cert.pem; ssl_certificate_key /opt/C2C/certs/key.pem; listen 443 ssl; server_name ctl.mydomain.com; location / { proxy_pass; proxy_http_version 1.1; # adds gzip gzip_static on; } }
  2. Reposted from https://3mrgnc3.ninja I thought some in the Hak5 forum community might like this too. C0m80 Boot2Root This is my third public Boot2Root, This one is intended to be quite difficult compared to the last two. But again, that being said, it will depend on you how hard it is :D The theme with this one is all about ‘enumeration, enumeration, enumeration’, lateral thinking, and how to “combine” vulnerabilities in order to exploit a system. Important Note Once you have an IP insert it into your attack system /etc/hosts like this: [dhcp-ip-address] C0m80.ctf This VM will probably be different to other challenges you may have come across. With C0m80 You will be required to log in locally in the VirtualBox console window at some point. This, I know, may ‘rile’ some of the purists out there that say you should be able to compromise a boot2root fully remotely over a network. I agree to that in principle, and in this case I had intended to allow vnc or xrdp access. Alas, due to compatibility problems I had to make a compromise in this area in order to get the challenge published sooner rather than later. It should be obvious at what point you need to log in. So when that time comes just pretend you are using remote desktop. ;D Sorry, I hope you can forgive me. Difficulty Rating [Difficult] Get to The Root Flag There is only one goal here. Become God on the system and read the root flag. I Hope You Enjoy It. Download https://3mrgnc3.ninja/2017/09/c0m80 Details File: C0m80_3mrgnc3-v1.0.ova OS: WondawsXP ;D VM Type: VirtualBox IP Address: DHCP Size: 2.7 GB Walkthroughs Please leave feedback and comments below. Including any info on walkthroughs anyone wishes to publish, or bugs people find in the VM Image. Good Luck & TryHarder ;D
  3. I think you are confused Ekber48 The Lan Turtle won't automatically hack into computers on the same lan. Rather, in the configuration you suggest, it gives you a foothold on the lan. Then from there you are able to conduct furter recon/spoofing/sniffing/mitm activity. The Lan Turtle can be used to attack a host directly via its usb in various ways but that requires a diferent use case from what you described. if you connect the turtle to any device via the RJ45/ethernet port, the network/computer/server (whatever you wish to call it) needs to assign an IP address to the turtle because it will request one via its dhcp client. It is possible to statically assign the ip beforehand if you know the target subnet is and what addresses are available. but that could cause problems.
  4. Hi digip, I sent you a DM on twitter mate. I messed up the clue for that flag. I've sent you a correction and will be updating the ova and my blog shortly today. As a point of note. The flags are not needed in order to root this box. They are really just designed as a parallel challenge to tackle. I have made some of the flags very tricky to find. Cheers.
  5. Still no walkthroughs submitted as of yet. If anyone has done one, please either tweet it to @3mrgnc3 or email me at 3mrgnc3@techie.com.
  6. That's a shame. Are you attacking from a VM with limited resources? What browser are you using? Going through the code will obviously work too though.
  7. Nice :D Glad you like it digip.
  8. New VM just sent in... to Vulnhub.com but here is a link for anyone who is into all that and wants to try it out now. D0Not5top Boot2Root This is my second public Boot2Root, It’s intended to be a little more difficult that the last one I made. That being said, it will depend on you how hard it is :D It's filled with a few little things to make the player smile. Again there are a few “Red Herrings”, and enumeration is key. DIFFICULTY ????? CAPTURE THE FLAGS There are 7 flags to collect, designed to get progressively more difficult to obtain DETAILS File: D0Not5top_3mrgnc3_v1.0.ova OS: ????? VM Type: VirtualBox IP Address: DHCP Size: 700 MB DOWNLOAD https://3mrgnc3.ninja/files/D0Not5top_3mrgnc3_v1.0.ova SUPPORT Any support issues can be directed to 3mrgnc3@techie.com SCREENSHOT I hope you all enjoy it! 3mrgnc3 ;D P.s. my previous challenge can be found here. https://3mrgnc3.ninja/2016/12/64base/ ------------------------------------------- NOTE: I Origionally posted this in 'everything else' forum but wanted to move it here. Not sure how to do that... Mods please feel free to remove origional.
  9. Very nice job... I was gonna have a go at this one but got distracted with work and other stuff. Very cool theme.
  10. There is a project I found on github that is a fail2ban style solution for opewrt that would probably work on the pineapple https://github.com/robzr/bearDropper Edit: lol just saw this was the same as suggested above too :D However, the issue with fail2ban's blacklisting style solution to the problem is that it ends up appending hundreds and hundreds of IP addresses to an iptables rule list. Then this has to be loaded/parsed/compared whenever connection attempts are made. This could give a significant performance hit to you little old pineapple. The simplest and least CPU intensive solution to the problem is to switch ssh to a high port (eg. 61222) AND use RSA key authentication, STRICTLY disallowing password auth in your config. Then (as just_a_user alluded to) WHITELIST you own IP addresses using iptables. The ssh BOT/BOTS that are trying to brute you tend only to focus on port 22, and if they are smart enough to detect password auth is dsabled will give up quickly. But in 99.9% of cases I would put money on the problem going away if your using a non standard high port number for ssh. Hope this helps.
  11. lol, Oh Yeah , Forgot about that when thinking about what I saw on my VPS, cheers for posting and letting people know I was mistaken in suggesting those particular commands.
  12. I grep then use sed (No logs left in home dir)
  13. I don't know about the pineapple, as I don't leave any of mine connected to the internet for a long period of time. However, on the VPS I run my blog from I was seeing many connections 'ESTABLISHED' to port 22 in netstat output. After also looking at my auth.log files too I saw Chinese IP addresses attempting to brute force my ssh password (unlucky for them I disable passwords and only use rsa keys). Sadly, this is common behaviour now in this age of cyberwarfare. I changed my ssh port to a non-standard one and now I have no problems. Just so everyone is clear, a netstat connection 'ESTABLISHED' doesn't mean an ssh session has been 'AUTHENTICATED'. Check using the commands: 'w', 'last', & 'lastlog' Then you will see precisely who is/has connected to your server and when.
  • Create New...