{"id":382,"date":"2024-01-29T20:45:28","date_gmt":"2024-01-30T02:45:28","guid":{"rendered":"https:\/\/blog.ishsome.com\/?p=382"},"modified":"2024-04-16T20:55:03","modified_gmt":"2024-04-17T01:55:03","slug":"reveal-hidden-files-in-google-storage","status":"publish","type":"post","link":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/29\/reveal-hidden-files-in-google-storage\/","title":{"rendered":"Reveal Hidden Files in Google Storage"},"content":{"rendered":"\n<p>This blog is based on the free lab provided by <a href=\"https:\/\/pwnedlabs.io\/labs\/reveal-hidden-files-in-google-storage\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" title=\"pwnedLabs\">PwnedLabs<\/a>. PwnedLabs provides a lot of free labs to practice in the cloud environment on platforms such as AWS, GCP, and Azure. The lab showcases how Cloud storage can be easy to misconfigure and misuse, and there is also a school of thought that it should instead be split into public storage and private storage services. Where a bucket stores a mix of public and private content, the risk is unauthorized access and a possible breach.<\/p>\n\n\n\n<p>Let&#8217;s dive into it! First, we need to download the VPN file and connect via OpenVPN.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a03b0d0484ee&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a03b0d0484ee\" class=\"wp-block-image size-large wp-lightbox-container\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"595\" data-attachment-id=\"383\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/29\/reveal-hidden-files-in-google-storage\/image-55\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?fit=1831%2C1064&amp;ssl=1\" data-orig-size=\"1831,1064\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-55\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?fit=1024%2C595&amp;ssl=1\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?resize=1024%2C595&#038;ssl=1\" alt=\"\" class=\"wp-image-383\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?resize=1024%2C595&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?resize=300%2C174&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?resize=768%2C446&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?resize=1536%2C893&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?resize=600%2C349&amp;ssl=1 600w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-55.png?w=1831&amp;ssl=1 1831w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ sudo openvpn pwnedlabs.ovpn \n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">sudo<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">openvpn<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">pwnedlabs.ovpn<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Once, you get the IP address for the tun adapter, we should be able to interact with the lab. Toggle the On\/Off switch to turn ON the lab and you will see the entry point&#8211;which is a web URL in this case.<\/p>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"421\" data-attachment-id=\"384\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/29\/reveal-hidden-files-in-google-storage\/image-56\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?fit=1803%2C742&amp;ssl=1\" data-orig-size=\"1803,742\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-56\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?fit=1024%2C421&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?resize=1024%2C421&#038;ssl=1\" alt=\"\" class=\"wp-image-384\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?resize=1024%2C421&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?resize=300%2C123&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?resize=768%2C316&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?resize=1536%2C632&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?resize=600%2C247&amp;ssl=1 600w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-56.png?w=1803&amp;ssl=1 1803w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Web Server Enumeration<\/mark><\/h3>\n\n\n\n<p>Going to the link provided, we see the following web page.<\/p>\n\n\n\n<div style=\"height:19px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"552\" data-attachment-id=\"385\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/29\/reveal-hidden-files-in-google-storage\/image-57\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?fit=2250%2C1212&amp;ssl=1\" data-orig-size=\"2250,1212\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-57\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?fit=1024%2C552&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?resize=1024%2C552&#038;ssl=1\" alt=\"\" class=\"wp-image-385\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?resize=1024%2C552&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?resize=300%2C162&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?resize=768%2C414&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?resize=1536%2C827&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?resize=2048%2C1103&amp;ssl=1 2048w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-57.png?resize=600%2C323&amp;ssl=1 600w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:19px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Viewing the page source, there is a comment that reveals some interesting information.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"89\" data-attachment-id=\"386\" data-permalink=\"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/29\/reveal-hidden-files-in-google-storage\/image-58\/\" data-orig-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?fit=1652%2C143&amp;ssl=1\" data-orig-size=\"1652,143\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-58\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?fit=1024%2C89&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?resize=1024%2C89&#038;ssl=1\" alt=\"\" class=\"wp-image-386\" srcset=\"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?resize=1024%2C89&amp;ssl=1 1024w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?resize=300%2C26&amp;ssl=1 300w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?resize=768%2C66&amp;ssl=1 768w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?resize=1536%2C133&amp;ssl=1 1536w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?resize=600%2C52&amp;ssl=1 600w, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-58.png?w=1652&amp;ssl=1 1652w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The subdomain <code>storage.googleapis.com<\/code> belongs to the Google Storage service, while <code>it-storage-bucket<\/code> is the name of the bucket. The name of the bucket doesn&#8217;t seem like it&#8217;s just dedicated to website resources&#8230; let&#8217;s check it out.<\/p>\n\n\n\n<p>We can install the Google Cloud CLI here: https:\/\/cloud.google.com\/sdk\/docs\/install-sdk. Once it&#8217;s installed, go ahead and authenticate with a personal Google account.<\/p>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>The link has all the instructions we need to install Google Cloud CLI on Linux<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">gcloud auth login<\/mark><\/h3>\n\n\n\n<p>Attempting to list the bucket contents using the <code>gcloud<\/code> command returns an access denied error. Specifically, it seems that we (public users) don&#8217;t have the <code>storage.buckets.get<\/code> permission on the resource.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ gcloud storage buckets list gs:\/\/it-storage-bucket\/ \nERROR: (gcloud.storage.buckets.list) User [someone@gmail.com] does not have permission to access b instance [it-storage-bucket] (or it may not exist): someone@gmail.com does not have storage.buckets.get access to the Google Cloud Storage bucket. Permission 'storage.buckets.get' denied on resource (or it may not exist).\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">gcloud<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">storage<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">buckets<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">list<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">gs:\/\/it-storage-bucket\/<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">ERROR:<\/span><span style=\"color: #BABED8\"> (gcloud.storage.buckets.list) User <\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">someone@gmail.com<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> does not have permission to access b instance <\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">it-storage-bucket<\/span><span style=\"color: #89DDFF\">]<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">or<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">it<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">may<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">exist<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\">: someone@gmail.com does not have storage.buckets.get access to the Google Cloud Storage bucket. Permission <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">storage.buckets.get<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\"> denied on resource <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">or<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">it<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">may<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">exist<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\">.<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Although we can&#8217;t list the bucket and see what else is stored there (apart from examining website links), Cloud Storage operations use names to identify buckets and objects. Therefore, we can try to make requests to potential file and folder names and infer their existence by analyzing the response codes received. Seeing the generic name of the bucket, we can think of looking for IT-related files.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">FFUF<\/mark><\/h4>\n\n\n\n<p>Backup files can be an attractive enumeration target as they often contain source code, credentials and other sensitive data. We can download the wordlist below that contains a list of common backup file names. It&#8217;s a good idea to maintain your file of discovered files and directories that you find on engagements.<\/p>\n\n\n\n<p>First, let&#8217;s download the wordlist that contains a list of backup files using wget.<\/p>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"wget https:\/\/raw.githubusercontent.com\/xajkep\/wordlists\/master\/discovery\/backup_files_only.txt\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">wget<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">https:\/\/raw.githubusercontent.com\/xajkep\/wordlists\/master\/discovery\/backup_files_only.txt<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<p>Now, we can run <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">ffuf <\/mark><\/em><\/strong>to begin brute-forcing the directories looking for backup files.<\/p>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ ffuf -w backup_files_only.txt -u https:\/\/storage.googleapis.com\/it-storage-bucket\/FUZZ -mc 200 -c\n\n        \/'___\\  \/'___\\           \/'___\\       \n       \/\\ \\__\/ \/\\ \\__\/  __  __  \/\\ \\__\/       \n       \\ \\ ,__\\\\ \\ ,__\\\/\\ \\\/\\ \\ \\ \\ ,__\\      \n        \\ \\ \\_\/ \\ \\ \\_\/\\ \\ \\_\\ \\ \\ \\ \\_\/      \n         \\ \\_\\   \\ \\_\\  \\ \\____\/  \\ \\_\\       \n          \\\/_\/    \\\/_\/   \\\/___\/    \\\/_\/       \n\n       v2.1.0-dev\n________________________________________________\n\n :: Method           : GET\n :: URL              : https:\/\/storage.googleapis.com\/it-storage-bucket\/FUZZ\n :: Wordlist         : FUZZ: \/home\/ishsome\/PwnedLabs\/backup_files_only.txt\n :: Follow redirects : false\n :: Calibration      : false\n :: Timeout          : 10\n :: Threads          : 40\n :: Matcher          : Response status: 200\n________________________________________________\n\nbackup.7z               [Status: 200, Size: 22072, Words: 102, Lines: 101, Duration: 276ms]\n:: Progress: [1015\/1015] :: Job [1\/1] :: 282 req\/sec :: Duration: [0:00:04] :: Errors: 0 ::\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">ffuf<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-w<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">backup_files_only.txt<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-u<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">https:\/\/storage.googleapis.com\/it-storage-bucket\/FUZZ<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-mc<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">200<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">-c<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">        <\/span><span style=\"color: #FFCB6B\">\/<\/span><span style=\"color: #FFCB6B\">&#39;___\\  \/&#39;<\/span><span style=\"color: #FFCB6B\">___\\<\/span><span style=\"color: #BABED8\">           <\/span><span style=\"color: #C3E88D\">\/<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">___\\       <\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">       \/\\ \\__\/ \/\\ \\__\/  __  __  \/\\ \\__\/       <\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">       \\ \\ ,__\\\\ \\ ,__\\\/\\ \\\/\\ \\ \\ \\ ,__\\      <\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">        \\ \\ \\_\/ \\ \\ \\_\/\\ \\ \\_\\ \\ \\ \\ \\_\/      <\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">         \\ \\_\\   \\ \\_\\  \\ \\____\/  \\ \\_\\       <\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">          \\\/_\/    \\\/_\/   \\\/___\/    \\\/_\/       <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">       v2.1.0-dev<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">________________________________________________<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\"> :: Method           : GET<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\"> :: URL              : https:\/\/storage.googleapis.com\/it-storage-bucket\/FUZZ<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\"> :: Wordlist         : FUZZ: \/home\/ishsome\/PwnedLabs\/backup_files_only.txt<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\"> :: Follow redirects : false<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\"> :: Calibration      : false<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\"> :: Timeout          : 10<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\"> :: Threads          : 40<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\"> :: Matcher          : Response status: 200<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">________________________________________________<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">backup.7z               [Status: 200, Size: 22072, Words: 102, Lines: 101, Duration: 276ms]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C3E88D\">:: Progress: [1015\/1015] :: Job [1\/1] :: 282 req\/sec :: Duration: [0:00:04] :: Errors: 0 ::<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Let&#8217;s download the backup.7z file using wget.<\/p>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ wget https:\/\/storage.googleapis.com\/it-storage-bucket\/backup.7z\n--2024-01-29 20:25:52--  https:\/\/storage.googleapis.com\/it-storage-bucket\/backup.7z\nResolving storage.googleapis.com (storage.googleapis.com)... 142.251.33.91, 142.250.217.91, 142.250.217.123, ...\nConnecting to storage.googleapis.com (storage.googleapis.com)|142.251.33.91|:443... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 22072 (22K) [application\/octet-stream]\nSaving to: \u2018backup.7z\u2019\n\nbackup.7z              100%[===========================&gt;]  21.55K  --.-KB\/s    in 0.1s    \n\n2024-01-29 20:25:53 (199 KB\/s) - \u2018backup.7z\u2019 saved [22072\/22072]\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">wget<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">https:\/\/storage.googleapis.com\/it-storage-bucket\/backup.7z<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">--2024-01-29<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">20<\/span><span style=\"color: #C3E88D\">:25:52--<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">https:\/\/storage.googleapis.com\/it-storage-bucket\/backup.7z<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Resolving<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">storage.googleapis.com<\/span><span style=\"color: #BABED8\"> (storage.googleapis.com)... 142.251.33.91, 142.250.217.91, 142.250.217.123, ...<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Connecting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">storage.googleapis.com<\/span><span style=\"color: #BABED8\"> (storage.googleapis.com)<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">142.251.33.91<\/span><span style=\"color: #89DDFF\">|<\/span><span style=\"color: #FFCB6B\">:443...<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">connected.<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">HTTP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">request<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">sent,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">awaiting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">response...<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">200<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OK<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Length:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">22072<\/span><span style=\"color: #BABED8\"> (22K) <\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">application\/octet-stream<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Saving<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">\u2018backup.7z\u2019<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">backup.7z<\/span><span style=\"color: #BABED8\">              <\/span><span style=\"color: #F78C6C\">100<\/span><span style=\"color: #C3E88D\">%[==========================<\/span><span style=\"color: #BABED8\">=<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #C3E88D\">]<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #F78C6C\">21.55<\/span><span style=\"color: #C3E88D\">K<\/span><span style=\"color: #BABED8\">  <\/span><span style=\"color: #C3E88D\">--.-KB\/s<\/span><span style=\"color: #BABED8\">    <\/span><span style=\"color: #C3E88D\">in<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">0.1<\/span><span style=\"color: #C3E88D\">s<\/span><span style=\"color: #BABED8\">    <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">2024-01-29<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">20<\/span><span style=\"color: #C3E88D\">:25:53<\/span><span style=\"color: #BABED8\"> (199 <\/span><span style=\"color: #C3E88D\">KB\/s<\/span><span style=\"color: #BABED8\">) - \u2018backup.7z\u2019 saved <\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #F78C6C\">22072<\/span><span style=\"color: #BABED8\">\/22072<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:13px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>We can now extract the file using 7z.<\/p>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ 7z x backup.7z \n\n7-Zip 23.01 (x64) : Copyright (c) 1999-2023 Igor Pavlov : 2023-06-20\n 64-bit locale=C.UTF-8 Threads:4 OPEN_MAX:1024\n\nScanning the drive for archives:\n1 file, 22072 bytes (22 KiB)\n\nExtracting archive: backup.7z\n--\nPath = backup.7z\nType = 7z\nPhysical Size = 22072\nHeaders Size = 232\nMethod = LZMA2:16 7zAES\nSolid = +\nBlocks = 1\n\n    \nEnter password (will not be echoed):\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">7<\/span><span style=\"color: #C3E88D\">z<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">x<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">backup.7z<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">7-Zip<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">23.01<\/span><span style=\"color: #BABED8\"> (x64) <\/span><span style=\"color: #82AAFF\">:<\/span><span style=\"color: #BABED8\"> Copyright <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">c<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\"> 1999-2023 Igor Pavlov <\/span><span style=\"color: #82AAFF\">:<\/span><span style=\"color: #BABED8\"> 2023-06-20<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\"> <\/span><span style=\"color: #FFCB6B\">64-bit<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">locale=C.UTF-8<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Threads:4<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OPEN_MAX:1024<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Scanning<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">drive<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">archives:<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">file,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">22072<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">bytes<\/span><span style=\"color: #BABED8\"> (22 <\/span><span style=\"color: #C3E88D\">KiB<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Extracting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">archive:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">backup.7z<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">--<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Path<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">backup.7z<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Type<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">7<\/span><span style=\"color: #C3E88D\">z<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Physical<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Size<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">22072<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Headers<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Size<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">232<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Method<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">LZMA2:16<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">7<\/span><span style=\"color: #C3E88D\">zAES<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Solid<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">+<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Blocks<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">=<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">    <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Enter<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #BABED8\"> (will <\/span><span style=\"color: #C3E88D\">not<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">be<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">echoed<\/span><span style=\"color: #BABED8\">):<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>The file is encrypted with a password. We need to extract the password before we can uncompress it. Let&#8217;s use the <strong><em><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">John-the-ripper<\/mark><\/em><\/strong> tool to extract the password.<\/p>\n\n\n\n<div style=\"height:11px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ 7z2john backup.7z &gt; backup.hash\nATTENTION: the hashes might contain sensitive encrypted data. Be careful when sharing or posting these hashes\n                                                                                           \n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ cat backup.hash \nbackup.7z:$7z$2$19$0$$8$1090375a5c67675f0000000000000000$3425971665$21840$21837$f4241ca97e603bf4f3e6375e64c70a8a3f335cbbcbdf16 ..&lt;SNIPPED&gt;..\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">7<\/span><span style=\"color: #C3E88D\">z2john<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">backup.7z<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">backup.hash<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">ATTENTION:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hashes<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">might<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">contain<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">sensitive<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">encrypted<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">data.<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Be<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">careful<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">when<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">sharing<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">or<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">posting<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">these<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hashes<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                                                                           <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cat<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">backup.hash<\/span><span style=\"color: #BABED8\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">backup.7z:$7z$2$19$0$$8$1090375a5c67675f0000000000000000$3425971665$21840$21837$f4241ca97e603bf4f3e6375e64c70a8a3f335cbbcbdf16<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">..<\/span><span style=\"color: #89DDFF\">&lt;<\/span><span style=\"color: #C3E88D\">SNIPPE<\/span><span style=\"color: #BABED8\">D<\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #C3E88D\">..<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:17px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-jetpack-markdown\"><blockquote>\n<p>I tried cracking the hash using the rockyou.txt file but was unable to extract it. We are required to create our custom wordlist using cewl.<\/p>\n<\/blockquote>\n<\/div>\n\n\n\n<div style=\"height:19px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ cewl https:\/\/careers.gigantic-retail.com\/index.html &gt; wordlist.txt\n                                                                                           \n\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ head wordlist.txt                            \nCeWL 6.1 (Max Length) Robin Wood (robin@digi.ninja) (https:\/\/digi.ninja\/)\nand\nJoin\nopportunities\nyour\ncareer\nnavbar\nYour\nCareer\nOur\n\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cewl<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">https:\/\/careers.gigantic-retail.com\/index.html<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&gt;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">wordlist.txt<\/span><\/span>\n<span class=\"line\"><span style=\"color: #BABED8\">                                                                                           <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">head<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">wordlist.txt<\/span><span style=\"color: #BABED8\">                            <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">CeWL<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">6.1<\/span><span style=\"color: #BABED8\"> (Max <\/span><span style=\"color: #C3E88D\">Length<\/span><span style=\"color: #BABED8\">) Robin Wood <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">robin@digi.ninja<\/span><span style=\"color: #89DDFF\">)<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">(<\/span><span style=\"color: #FFCB6B\">https:\/\/digi.ninja\/<\/span><span style=\"color: #89DDFF\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">and<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Join<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">opportunities<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">your<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">career<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">navbar<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Your<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Career<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Our<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:14px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Running John again with this wordlist, we can get the password in just a few seconds!<\/p>\n\n\n\n<div style=\"height:18px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ john backup.hash --wordlist=wordlist.txt                          \nUsing default input encoding: UTF-8\nLoaded 1 password hash (7z, 7-Zip archive encryption [SHA256 128\/128 SSE2 4x AES])\nCost 1 (iteration count) is 524288 for all loaded hashes\nCost 2 (padding size) is 3 for all loaded hashes\nCost 3 (compression type) is 2 for all loaded hashes\nCost 4 (data length) is 21837 for all loaded hashes\nWill run 4 OpenMP threads\nPress 'q' or Ctrl-C to abort, almost any other key for status\nbalance          (backup.7z)     \n1g 0:00:00:04 DONE (2024-01-29 20:40) 0.2207g\/s 24.72p\/s 24.72c\/s 24.72C\/s being..achieve\nUse the &quot;--show&quot; option to display all of the cracked passwords reliably\nSession completed. \" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">john<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">backup.hash<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">--wordlist=wordlist.txt<\/span><span style=\"color: #BABED8\">                          <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Using<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">default<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">input<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">encoding:<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">UTF-8<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Loaded<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">password<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">hash<\/span><span style=\"color: #BABED8\"> (7z, <\/span><span style=\"color: #F78C6C\">7<\/span><span style=\"color: #C3E88D\">-Zip<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">archive<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">encryption<\/span><span style=\"color: #BABED8\"> [SHA256 <\/span><span style=\"color: #F78C6C\">128<\/span><span style=\"color: #C3E88D\">\/128<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">SSE2<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #C3E88D\">x<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">AES]<\/span><span style=\"color: #BABED8\">)<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Cost<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">1<\/span><span style=\"color: #BABED8\"> (iteration <\/span><span style=\"color: #C3E88D\">count<\/span><span style=\"color: #BABED8\">) is 524288 <\/span><span style=\"color: #89DDFF; font-style: italic\">for<\/span><span style=\"color: #BABED8\"> all loaded hashes<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Cost<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">2<\/span><span style=\"color: #BABED8\"> (padding <\/span><span style=\"color: #C3E88D\">size<\/span><span style=\"color: #BABED8\">) is 3 <\/span><span style=\"color: #89DDFF; font-style: italic\">for<\/span><span style=\"color: #BABED8\"> all loaded hashes<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Cost<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">3<\/span><span style=\"color: #BABED8\"> (compression <\/span><span style=\"color: #C3E88D\">type<\/span><span style=\"color: #BABED8\">) is 2 <\/span><span style=\"color: #89DDFF; font-style: italic\">for<\/span><span style=\"color: #BABED8\"> all loaded hashes<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Cost<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #BABED8\"> (data <\/span><span style=\"color: #C3E88D\">length<\/span><span style=\"color: #BABED8\">) is 21837 <\/span><span style=\"color: #89DDFF; font-style: italic\">for<\/span><span style=\"color: #BABED8\"> all loaded hashes<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Will<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">run<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">4<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">OpenMP<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">threads<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Press<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #C3E88D\">q<\/span><span style=\"color: #89DDFF\">&#39;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">or<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Ctrl-C<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">abort,<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">almost<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">any<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">other<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">key<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">for<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">status<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">balance<\/span><span style=\"color: #BABED8\">          (backup.7z)     <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">1g<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #F78C6C\">0<\/span><span style=\"color: #C3E88D\">:00:00:04<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">DONE<\/span><span style=\"color: #BABED8\"> (2024-01-29 <\/span><span style=\"color: #F78C6C\">20<\/span><span style=\"color: #C3E88D\">:40<\/span><span style=\"color: #BABED8\">) 0.2207g\/s 24.72p\/s 24.72c\/s 24.72C\/s being..achieve<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Use<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #C3E88D\">--show<\/span><span style=\"color: #89DDFF\">&quot;<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">option<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">to<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">display<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">all<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">of<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">the<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">cracked<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">passwords<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">reliably<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Session<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">completed.<\/span><span style=\"color: #BABED8\"> <\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<div style=\"height:12px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Extracting the archive and providing the password, we find the names and home addresses of Gigantic Retail customers! We can also get the flag for this challenge.<\/p>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:block;padding:16px 0 0 16px;margin-bottom:-1px;width:100%;text-align:left;background-color:#0F111A\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"54\" height=\"14\" viewBox=\"0 0 54 14\"><g fill=\"none\" fill-rule=\"evenodd\" transform=\"translate(1 1)\"><circle cx=\"6\" cy=\"6\" r=\"6\" fill=\"#FF5F56\" stroke=\"#E0443E\" stroke-width=\".5\"><\/circle><circle cx=\"26\" cy=\"6\" r=\"6\" fill=\"#FFBD2E\" stroke=\"#DEA123\" stroke-width=\".5\"><\/circle><circle cx=\"46\" cy=\"6\" r=\"6\" fill=\"#27C93F\" stroke=\"#1AAB29\" stroke-width=\".5\"><\/circle><\/g><\/svg><\/span><span role=\"button\" tabindex=\"0\" data-code=\"\u250c\u2500\u2500(ishsome\u327fkali)-[~\/PwnedLabs]\n\u2514\u2500$ head customers-credit-review.csv                                  \nfirst_name,last_name,address,city,county,state,zip,phone1,phone2,email\nJames,Butt,6649 N Blue Gum St,New Orleans,Orleans,LA,70116,504-621-8927,504-845-1427,jbutt@gmail.com\nJosephine,Darakjy,4 B Blue Ridge Blvd,Brighton,Livingston,MI,48116,810-292-9388,810-374-9840,josephine_darakjy@darakjy.org\nArt,Venere,8 W Cerritos Ave #54,Bridgeport,Gloucester,NJ,8014,856-636-8749,856-264-4130,art@venere.org\n..&lt;SNIPPED&gt;..\" style=\"color:#babed8;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki material-theme-ocean\" style=\"background-color: #0F111A\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #FFCB6B\">\u250c\u2500\u2500(ishsome\u327fkali<\/span><span style=\"color: #BABED8\">)-<\/span><span style=\"color: #89DDFF\">[<\/span><span style=\"color: #BABED8\">~\/PwnedLabs<\/span><span style=\"color: #89DDFF\">]<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">\u2514\u2500$<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">head<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">customers-credit-review.csv<\/span><span style=\"color: #BABED8\">                                  <\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">first_name,last_name,address,city,county,state,zip,phone1,phone2,email<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">James,Butt,6649<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">N<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Blue<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Gum<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">St,New<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Orleans,Orleans,LA,70116,504-621-8927,504-845-1427,jbutt@gmail.com<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Josephine,Darakjy,4<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">B<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Blue<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Ridge<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Blvd,Brighton,Livingston,MI,48116,810-292-9388,810-374-9840,josephine_darakjy@darakjy.org<\/span><\/span>\n<span class=\"line\"><span style=\"color: #FFCB6B\">Art,Venere,8<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">W<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Cerritos<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #C3E88D\">Ave<\/span><span style=\"color: #BABED8\"> <\/span><span style=\"color: #464B5D; font-style: italic\">#54,Bridgeport,Gloucester,NJ,8014,856-636-8749,856-264-4130,art@venere.org<\/span><\/span>\n<span class=\"line\"><span style=\"color: #82AAFF\">..<\/span><span style=\"color: #BABED8\">&lt;SNIPPED&gt;<\/span><span style=\"color: #82AAFF\">..<\/span><\/span><\/code><\/pre><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-luminous-vivid-amber-color\">Defense<\/mark><\/h3>\n\n\n\n<p>Multiple security oversights contributed to this breach, and while each may seem small, combined they had a huge impact. In such scenarios, the reputation damage and fines issued by regulators can be very severe.<\/p>\n\n\n\n<p>Firstly the commented-out code disclosed the name of the Google Storage bucket that was hosting the website. From there we found that a backup file was discoverable and accessible from anywhere on the internet, provided they know the file name. The backup file was encrypted with a very weak password that was not resilient to offline cracking. It was then found that the file contained unencrypted PII (personally identifiable information), including the names and home addresses of Gigantic Retail customers.<\/p>\n\n\n\n<p>Cloud storage should either be used to make resources publicly accessible, such as a website, or used to store resources that should only be privately accessible. The bucket should have been used for the single purpose of serving a website. This would help avoid private files being stored on a bucket that is accessible on the internet. Naming the bucket in line with its purpose could help to reduce confusion about what files should be stored there. However, predictable naming conventions or names that provide threat actors with information is also problematic. The recommendation from cloud storage providers is to use per-project random codenames such as <code>deltaorangestouchdown-prod<\/code> to name the buckets.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This blog is based on the free lab provided by PwnedLabs. PwnedLabs provides a lot of free labs to practice in the cloud environment on platforms such as AWS, GCP, and Azure. The lab showcases how Cloud storage can be easy to misconfigure and misuse, and there is also a school of thought that it [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1,49,11,37,35],"tags":[],"class_list":["post-382","post","type-post","status-publish","format-standard","hentry","category-blog","category-ctf","category-ctf-write-ups","category-gcp","category-pwned-labs"],"aioseo_notices":[],"featured_image_src":null,"author_info":{"display_name":"ishsome","author_link":"https:\/\/blog.ishsome.com\/index.php\/author\/e5c77740144cd4a8\/"},"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":813,"url":"https:\/\/blog.ishsome.com\/index.php\/2026\/01\/06\/install-qradar-community-edition-in-proxmox\/","url_meta":{"origin":382,"position":0},"title":"Install QRadar Community Edition in Proxmox","author":"ishsome","date":"January 6, 2026","format":false,"excerpt":"In this post, I walk through the process of installing IBM QRadar Community Edition on a Proxmox server in my home lab. This setup helps me explore QRadar\u2019s features, understand its architecture, and gain hands-on experience with one of the most widely used SIEM platforms in cybersecurity. In future blog\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2026\/01\/Pasted-image-20260104092108.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2026\/01\/Pasted-image-20260104092108.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2026\/01\/Pasted-image-20260104092108.jpg?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":638,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/06\/15\/palo-alto-firewall-initial-configuration\/","url_meta":{"origin":382,"position":1},"title":"Palo Alto Firewall: Initial Configuration","author":"ishsome","date":"June 15, 2024","format":false,"excerpt":"Embarking on the path to becoming a Network Security Engineer or already a seasoned Network Engineer interested in mastering Palo Alto firewalls? You've come to the right place. In this blog, we delve into the essential steps of configuring a Palo Alto firewall in EVE-NG, focusing on the initial setup.\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/06\/image-22.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/06\/image-22.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/06\/image-22.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/06\/image-22.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":434,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/02\/03\/what-is-log-poisoning\/","url_meta":{"origin":382,"position":2},"title":"What Is Log Poisoning?","author":"ishsome","date":"February 3, 2024","format":false,"excerpt":"Logs are records generated by various software applications, operating systems, and network devices to keep track of events and activities. They are essential for monitoring, troubleshooting, and security analysis. Log poisoning typically refers to malicious activities or techniques aimed at manipulating or contaminating log files in computer systems. Log poisoning\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":625,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/05\/09\/cve-2023-33831\/","url_meta":{"origin":382,"position":3},"title":"CVE-2023-33831","author":"ishsome","date":"May 9, 2024","format":false,"excerpt":"This vulnerability allowed remote command execution (RCE) vulnerability in the \/api\/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request. This is due to lack of control or sanitization on inputs that can be controlled by users, thus allowing the use of dangerous methods\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=1050%2C600&ssl=1 3x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/05\/image.png?resize=1400%2C800&ssl=1 4x"},"classes":[]},{"id":168,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/24\/tryhackme-bulletproof-penguin\/","url_meta":{"origin":382,"position":4},"title":"TryHackMe: Bulletproof Penguin","author":"ishsome","date":"January 24, 2024","format":false,"excerpt":"Bulletproof plugin\u00a0is an easy room that deals with hardening security on the common services that run on a Linux machine. This room covers services such as FTP, MySQL, Redis, SSH, etc., and how their configurations can be changed to secure them from unauthorized access. Our goal in each task is\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-32.png?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":306,"url":"https:\/\/blog.ishsome.com\/index.php\/2024\/01\/27\/http-request-smuggling\/","url_meta":{"origin":382,"position":5},"title":"HTTP Request Smuggling","author":"ishsome","date":"January 27, 2024","format":false,"excerpt":"This blog is based on the HHTP Request Smuggling room from TryHackMe. What is HTTP Request Smuggling? HTTP Request Smuggling is a vulnerability that arises when there are mismatches in different web infrastructure components. This includes proxies, load balancers, and servers that interpret the boundaries of HTTP requests. Request splitting\u2026","rel":"","context":"In &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/blog.ishsome.com\/index.php\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/blog.ishsome.com\/wp-content\/uploads\/2024\/01\/image-34.png?resize=1050%2C600&ssl=1 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/382","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/comments?post=382"}],"version-history":[{"count":3,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/382\/revisions"}],"predecessor-version":[{"id":390,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/posts\/382\/revisions\/390"}],"wp:attachment":[{"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/media?parent=382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/categories?post=382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ishsome.com\/index.php\/wp-json\/wp\/v2\/tags?post=382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}