.

Typo in challenge?

<<

Steven Hunter

Newbie
Newbie

Posts: 1

Joined: Wed Jul 12, 2006 12:54 pm

Post Wed Jul 12, 2006 1:01 pm

Typo in challenge?

Is this line a typo?

root@snakepit:~/  # nc -lp 5050 > apptrace


It seems to me, and quick tests seems to confirm, that this would never terminate. And yet we don't see evidence that O-Ren sent a ^C, ^Z, or escaped back to the shell in any way.

Or is that part of the challenge?  ;D
<<

mikepoor

Newbie
Newbie

Posts: 1

Joined: Wed Jul 12, 2006 4:11 pm

Post Wed Jul 12, 2006 4:20 pm

Re: Typo in challenge?

Steven
great question.  On the debian based systems that I was using (one was Ubuntu, the other Backtrack) the connection errors out as soon as you reach the end of file.  Otherwise you could use the -wN (where N is a number of seconds to wait before killing the connection).  The third option as you point out is to issue an interrupt character to the client or the server.

thanks!

Mike Poor
<<

don

User avatar

Administrator
Administrator

Posts: 4226

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Wed Jul 12, 2006 11:44 pm

Re: Typo in challenge?

We have also been contacted by other individuals interested in submitting answers to this challenge but were concerned because they were unfamiliar with the commands used by Mike Poor. Rest assured that both Ed Skoudis and Mike not only know a hell of a lot more than I do, but they also have tripled checked every line of the challenge. The preformatted text in the challenge is the actual dump from Mike's testing.

It is correct and it is meant to be just that... a challenge.

In fact, a missing space (that can't even be seen) was cutoff in the transfer of the challenge into html format. They caught it and made sure that I changed it. They're that good! :o

You have plenty of time to do research before submitting your answers. Remember - Google is your friend. So take your time and have fun with it. Along they way, we'll all be educated. ;D

Best of luck,
Don
CISSP, MCSE, CSTA, Security+ SME
<<

pcsneaker

Jr. Member
Jr. Member

Posts: 73

Joined: Mon Nov 07, 2005 12:23 pm

Post Thu Jul 13, 2006 11:05 am

Re: Typo in challenge?

Obviously you made the same mistake I made...

Read the challenge carefully, look for the not so obvious - after going over it thoroughly several times I can confirm that there is no typo, it works ! (tested on Debian Sarge 3.1)

I think that I've found the answers  ;D

BTW, shame on me that I had doubts on the accuracy. I ought to have known better that Mike and Ed certainly double and triple check what they publish.... 
MCSA:Security (W2k, W2k3)
MCSE:Security (W2k, W2k3)
CPTS, Network+
<<

Hug_It

Newbie
Newbie

Posts: 28

Joined: Thu Feb 23, 2006 4:21 pm

Post Wed Jul 19, 2006 1:03 pm

Re: Typo in challenge?

These things ARE really good learning tools. This was my first attempt and at first I wasn't really giving it's deserved attention but after really looking into it I was quite impressed with the level of detail that went into the scenario. Great stuff!
CISSP

Return to July 06 - Hack Bill!

Who is online

Users browsing this forum: No registered users and 1 guest

cron
.
Powered by phpBB® Forum Software © phpBB Group.
Designed by ST Software