Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 16 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Featuresarrow Skillzarrow Sept 06 - Netcat in the Hatarrow Skillz Sept 06 Winning Entry - Technical
Ethical Hacker Community Forums
August 28, 2008, 11:31:42 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Skillz Sept 06 Winning Entry - Technical  (Read 7448 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2229


Editor-In-Chief


View Profile WWW
« on: October 21, 2006, 01:47:51 PM »

Aaron Hertz

Quote
Here's my answers for the September 2006 Skillz Challenge:

1)  "Thing One" is dd, the file-manipulation swiss-army knife and fine companion of...
2)  "Thing Two", nc, the all purpose network swiss army knife.

3)  On horton.whoville.com, we run the command:

dd if=TPSDATA090106.zip skip=8227126 | nc -l -p 12345

This tells dd to output to read from our data file, skipping the first
8,227,126 512-byte blocks, and write to stdout.  Next in the pipeline, nc will listen for a connection to port 12345, and then spew the rest of the file down to whatever client connects.

Then, to receive the file on lumbergh.initech.com, we run:

nc horton.whoville.com 12345 >> TPSDATA090106.zip

This will connect to the listener we just created, and write the data it receives to the end of the data file.

(Of course, if we want to be really cute, and we're running a modern version of bash or ksh, we can do:

cat /dev/tcp/horton.whoville.com/12345 >> TPSDATA090106.zip

But, that would just be silly.  Smiley    )

This way we only transfer the missing piece of the file over the slow wireless link, minimizing the amount of data we transfer.  Why create the listener on horton.whoville.com?  Well, if the upstairs office has an open WAP, it's likely a cheap residential wireless router.  So, it's likely that we won't be able to get a TCP connection into lumbergh.initech.com.  Plus, we don't even know what our outside IP address is, and this way we don't have to bother to find out.

This does assume that the firewall in front of horton.whoville.com will allow connections to TCP port 12345.  If it doesn't, we can send our connection through an SSH tunnel.  When we connect from lumbergh to horton, we'd do something like:

ssh -L 12345:horton.whoville.com:12345 horton.whoville.com

We'd then run the same command on horton, but our command on lumbergh would then be:

nc localhost 12345 >> TPSDATA090106.zip

That way, the only incoming connection to horton.whoville.com is over port 22, which we know is allowed.

4)  The most straightforward solution is to adjust the block size used by dd.  We'd change the command on horton to be:

dd bs=1 if=TPSDATA090106.zip skip=4212288525 | nc -l -p 12345

This will, though, be more inefficient.  We'll be reading only one byte at a time from the file.  But, at least Nagle's algorithm will ensure that we don't send one-byte packets, which would be _horribly_ inefficient.

A more efficient way is to use tail.  The command:

tail -c +13 -

will skip the first 13 bytes of stdin, and print the rest.  That's exactly what we want.  So, our command on horton becomes:

dd if=TPSDATA090106.zip skip=8227126 | tail -c +13 - | nc -l -p 12345

- -----

This was a really fun challenge - and your Seussian poetry is brilliant.  I look forward to next month.  Smiley

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.042 seconds with 24 queries.
 

EH-Net's
2nd Annual
Tweener Party
 

Thanks all. Click HERE for details.

Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.