25 ms·
Israeli Mossad launches cyber challenge
- tdhoot 7y agoIn case you didn't want to wait for the slow-typing to load the entire message: "Welcome Agent. A team of field operatives is currently on-site in enemy territory, working to retrieve intel on an imminent terrorist attack. The intel is contained in a safe, the plans for which are available to authorized clients via an app [0]. Our client ID is d09ff4ec651c48f89f7f7aa19160bd55 Your mission is to retrieve those plans, and allow our team to break into the safe. Good luck!, M." [0]: http://3d375032374147a7865753e4bbc92682.xyz/static/app.apk http://3d375032374147a7865753e4bbc92682.xyz/static/app.apk
- ChuckNorris89 7y agoAre they seriously expecting people to sideload a mossad apk on their phones?
- nickelcitymario 7y agoIf you're dumb enough to do that... maybe they blacklist you from their recruitment efforts moving forward. You could always install it on a virtual phone in a sandboxed VM.
- dclusin 7y agoWhat do you do if they have sandbox escapes you don't know about? The kind of person that runs it in a VM is someone they'd probably want to be looking at. Paranoia++ :)
- deleted 7y ago[deleted]
- pmiller2 7y agoDownload to a burner machine, then airgap it by removing/disabling all networking hardware, inside a room with no other computers. ;)
- Scoundreller 7y agoThen sell the system to an unsuspecting soul on eBay.
- Paraesthetic 7y agoOr gumtree
- dontbenebby 7y agoI couldn't even get to refusing to trust an apk because their message doesn't render if you have a JS whitelisting extension such as NoScript.
- kps 7y agoIt's all in the page source, though.
- saagarjha 7y agoYou’re probably expected to load it into your favorite static analysis tool.
- TheLoneTechNerd 7y agoOf course not, it would be prohibitively difficult to deconstruct the apk from the phone itself.
- deleted 7y ago[deleted]
- chrismeller 7y agoInstall a random app from Mossad on my phone? N-no, no I don’t think so.
- Circuits 7y agolol my thoughts exactly...
- blattimwind 7y agoChallenge is obviously meant to be reversing, not installing.
- mrlatinos 7y agoIf you deconstruct the APK, you'll find a C script that prints a message - "You really think it was the Saudis? :)" /s
- rock_artist 7y agoSo far I've just used those decompile services online and it seems it's Flutter package com.iwalk.locksmither; import android.os.Bundle; import io.flutter.app.FlutterActivity; import io.flutter.plugins.GeneratedPluginRegistrant; public class MainActivity extends FlutterActivity { protected void onCreate(Bundle savedInstanceState) { super.onCreate(savedInstanceState); GeneratedPluginRegistrant.registerWith(this); } } In terms of permissions, it asks for INTERNET.
- 1f60c 7y agoHere's the VirusTotal page: https://www.virustotal.com/#/file/f422d8ceef1a2c3cd6cce10c834aa7cc994a95a4d695b16bf114e9e8ebb066d7/detection https://www.virustotal.com/#/file/f422d8ceef1a2c3cd6cce10c83...
- deleted 7y ago[deleted]
- 7y ago
- aerodog 7y agoWhen they say a terrorist attack - are they referencing themselves or...?
- salawat 7y agoOh, come on. You have to have an old phone lying around to factory reset for shits and giggles. Not like they'd burn good zero days on a publicity stunt. Remember, this thing'll be getting picked apart by everybody considering the source. Unless you're afraid of getting black bagged that i...<SIGNAL LOST>
- benburleson 7y agoYou don't need a 0-day when the target installs for you.
- Paraesthetic 7y agoChief.. Chief come in... Damn lost him
- Ritsuko_akagi 7y agoI hope my house does receive air strike
- chrischen 7y agoI think you mean “doesn’t”. OP is referring to the recent Israeli airstrike of suspected Hamas hacking group building.
- lone_haxx0r 7y agoI don't have time for slow-ass typing text. Next.
- mfatica 7y agoview page source mr hackerman
- lone_haxx0r 7y agoIf I need to read the source code of a fucking website for it to be useful, then it's either a really special edge-case or the designer is a moron. Guess which case this is. Why not upload a plain text file in the first place?
- mfatica 7y agobecause it's a hacking challenge website not a fucking blog. it's supposed to be thematic
- TheTruth1234 7y agoIt's pathetic.
- darkpuma 7y ago> it's either a really special edge-case Bingo!
- alphagrep12345 7y agoHow do you know it's by mossad?
- m_samuel_l 7y agoOnly one way to find out
- Polycryptus 7y agoOnce you solve the first challenge it tells you to send an email to an @gov.il email address, which confirms it pretty well for me.
- Naac 7y agoIgnoring the editorialized made up title of this post, is there any information on who actually made this challenge?
- stdcall83 7y agoSaved you the huss of reading hebrew, but actually the challenge starts at: https://www.mossad.gov.il/Pages/default.aspx https://www.mossad.gov.il/Pages/default.aspx You need to figure out the address of the site I posted from the picture. (Not that difficult)
- mrlatinos 7y agoCookies must be enabled... APK to install... Does curiosity really make ya'll this dumb?
- TheLoneTechNerd 7y agoLevel 1: The people who just go to the site/download the APK Level 2: The people who realize that the requested actions are likely unsafe, and complain about it Level 3: People who realize that this is part of the challenge and just use a VM Nobody on HN is "this dumb", if you want to participate in a challenge with an intelligence agency, take the proper precautions
- mrlatinos 7y agoThe majority of the population is Level 1. Consider what that means for Mossad. Enjoy your challenge.
- TheLoneTechNerd 7y ago"The majority of the population is Level 1" Yes, and those people might visit a website, which asks for...shudder...cookies. If you can show that the cookies do something nefarious, I'd be interested. Do you think they general population would even get to the point of installing an APK? "Consider what that means for Mossad" At this point, you can't even prove that the APK does anything nefarious - and it would be dangerous for the Mossad if it did, because the challenge is literally to decompile the APK.
- jakobov 7y agoHow do we know this is created by the mossad?
- deleted 7y ago[deleted]
- jsdev93 7y agoTHIS IS LEGITIMATE. The Israeli Mossad had a ad today, https://www.algemeiner.com/2019/05/09/mossad-marks-israeli-independence-day-with-facebook-riddle/ https://www.algemeiner.com/2019/05/09/mossad-marks-israeli-i... with a picture. The picture has 4 rows of trophies, which should be converted to 4 numbers using binary --> decimal. Those four numbers are 35, 246, 158, 51. As an ip address, 35.246.158.51 leads to the site OP posted.
- deleted 7y ago[deleted]
- hashberry 7y agoThis site loads the jQuery library in order to... 1. Access $("#text1")[0].innerHTML 2. $( document ).ready() { typeWriter (); } facepalm
- whoisjuan 7y agoIt's done like that because the typeWriter effect is actually rendering line break elements (<br>) as it shows up.
- hashberry 7y agowoosh, loading jQuery to access an element is not needed. document.getElementById would suffice.
- whoisjuan 7y agojQuery is still a valid way to manipulate the DOM. There’s nothing wrong with doing that, especially if you already need to load jQuery for something else. I don’t think this is what the comment was referring to.
- hashberry 7y agoThere's no reason to load a 30KB JavaScript library for such a simple webpage. See http://youmightnotneedjquery.com/ http://youmightnotneedjquery.com/
- laurentl 7y agoThe French cyber security community has a similar challenge every year: https://www.sstic.org/2019/challenge/ https://www.sstic.org/2019/challenge/ (in French). The challenges usually involve static analysis / disassembly, breaking improperly configured crypto, etc. The best part (for me at least) is that competitors must submit a write-up of how they cracked the challenge, and the best write-ups are published. It makes for fascinating reading even if you’re not really into that scene.
- atdt 7y agoDecompile the apk, and run 'strings' on assets/flutter_assets/kernel_blob.bin. Poke around and you'll find code for POSTing JSON-encoded credentials to http://35.246.158.51:8070/auth/getUrl http://35.246.158.51:8070/auth/getUrl. (Grep for the IP to find it.) So, using the web site name as the seed and the 'client id' as the password, we get: $ curl -X POST -H "Content-Type: application/json" -d '{"Seed": "3d375032374147a7865753e4bbc92682", "Password": "d7c6bdcfcb184bf587ceee7c7c28e72e"}' http://35.246.158.51:8070/auth/getUrl http://35.246.158.51:8070/auth/getUrl The response is an HTTP 200 and: {"AuthURL":"/auth/v2"} http://35.246.158.51:8070/auth/v2 http://35.246.158.51:8070/auth/v2 is I guess the next step. edit: The /auth/getUrl endpoint responds to any request with the same response, so that may not be the right Seed/Password combination.
- stdcall83 7y agoGot to this point by running the APK in sandbox and tracking the TCP packets...
- arboroia 7y agoYou're close, but that first endpoint is just to retrieve the auth URL, no need to post anything to it. It then passes the seed and password to the returned URL, so: "http://35.246.158.51:8070/auth/v2" http://35.246.158.51:8070/auth/v2" gets '{"Seed": "xxx", "Password": "xxx"}' of some kind I haven't yet figured out what those are though... See: Future<Token> login(String seed, String password) { var headers = new Map<String,String>(); return _netUtil.get(LOGIN_URL, headers:headers).then((dynamic authUrl) { try { if (authUrl == null) { return Future<Token>.sync(() => new Token("", false, 0)); } var loginUrl = BASE_URL + AuthURL.map(json.decode(authUrl.body)).url;
- arboroia 7y agoSo reading about flutter, there's quick reload information in debug mode[0] This leads me to believe that the seed and password entered in development / in the cookie jar from a previous attempt are somewhere in the `isolate_snapshot_data` file [0] https://github.com/flutter/flutter/wiki/Flutter-engine-operation-in-AOT-Mode https://github.com/flutter/flutter/wiki/Flutter-engine-opera...
- dannyy11 7y agoHey
- andr0id 7y agoSearching for "iWalk-v2" on google gives following book as the first result: https://books.google.rs/books?id=1nfhpqvLSM4C&pg=PA397&lpg=PA397&dq=%22iwalk-v2%22&source=bl&ots=oxE7LdoK2w&sig=ACfU3U1h4H0eUFMV2u3zk9VbR_kDiVw_vA&hl=sr&sa=X&ved=2ahUKEwilp4qM94_iAhXIb1AKHXS1CWsQ6AEwBnoECAkQAQ#v=onepage&q=%22iwalk-v2%22&f=false https://books.google.rs/books?id=1nfhpqvLSM4C&pg=PA397&lpg=P... on page 397 there is entry in index: iWalk, v2 71 on the same page there are interesting terms like islamic terrorism, jihad via internet, judism... also page number 71 which stands next to iWalk term is interesting coincidence since this riddle is celebrating 71 years of Israel independence...
- malian 7y agoייחייייעעעא
- malian 7y agoHhhhh
- DvirRonaldo 7y agoFirst Challenge Solution: Mossad 2019 Challenge Start: https://r-u-ready-4.it/ https://r-u-ready-4.it/ Every line in the image is binary 8-bit number that will give you an ip address : 35.246.158.51 Challenge-1 :Link http://3d375032374147a7865753e4bbc92682.xyz http://3d375032374147a7865753e4bbc92682.xyz / http://35.246.158.51 http://35.246.158.51 Download app.apk from http://3d375032374147a7865753e4bbc92682.xyz/static/app.apk http://3d375032374147a7865753e4bbc92682.xyz/static/app.apk Remember your Client ID - mine is 854279b4c89e4b5c9722352c3f9f1d6c You will user it as "Seeder" property in the app //////////////////////////////////////////////////////////////////////////////////////////////// using WireShark (or any other packet snipper) we can see that the login button does this: POST /auth/v2 HTTP/1.1si user-agent: iWalk-v2 content-type: application/json; charset=utf-8 accept-encoding: gzip content-length: 29 host: 35.246.158.51:8070 {"Seed":"admin","Password":"admin "}HTTP/1.1 200 OK Content-Type: application/json Date: Wed, 08 May 2019 21:49:05 GMT Content-Length: 47 {"IsValid":false,"LockURL":"","Time":149646302} /////////////////////////////////////////////////////// Using http://www.javadecompilers.com/ http://www.javadecompilers.com/, i Decompiled the apk, and got a lock at the Manifest < <xml version="1.0" encoding="utf-8" ....... <activity android:configChanges="density|fontScale|keyboard|keyboardHidden|layoutDirection|locale|orientation|screenLayout|screenSize" android:hardwareAccelerated="true" android:launchMode="singleTop" android:name="com.iwalk.locksmither.MainActivity" .... ..... The line "look for us on github.com" got my attention, so i looked for iwalk.locksmither in github and found "iwalk-locksmithers" linke: https://github.com/iwalk-locksmithers-app https://github.com/iwalk-locksmithers-app the server source code was there. In the code, there are a few comments that can help https://github.com/iwalk-locksmithers-app/server/blob/master/main.go https://github.com/iwalk-locksmithers-app/server/blob/master... link 70 points us to the auth-1 weeknes. the part of "for currentIndex < len(lock.Password) && currentIndex < len(loginData.Password) { if lock.Password[currentIndex] != loginData.Password[currentIndex] { break } //OG: securing against bruteforce attempts... ;-) time.Sleep(30 * time.Millisecond) currentIndex++ }" the securing aginst bruteforce (tyring all combinations) is the weeknes. The idea behind for hacking the password is to try only one char at first. if we get a 30ms dealy, it means we got the 1st char right, so then we can check the next one, so we will try 2 chars (the 1st we know, the second we will guess) if we will get 60 ms +- dealy then we got th 2nd char and we will try the third one, and again and again, until we will get the password. To solve it, it wrote a simple c# code that does in a loop http push to the server every time we try to add a new char to the password, and if we got a dealy that is +- 30ms more then the last try, we add that char our final password the uri is http://35.246.158.51:8070/auth/v1_1 http://35.246.158.51:8070/auth/v1_1 and user agent is ed9ae2c0-9b15-4556-a393-23d500675d4b (as writen in the server) I did some avg calcs of the dealys The password length is 32 with hexa char (didnt know that until i guessed the password) we can know that the password is correct when we get back "IsValid":true" *Time we get is in nano Seconds and not ms After I enterd the pasword and cliend id, i got a link for a token and a linke for challenge 2 http://759d8eba52184f538c8a4525680cfb33.xyz/ http://759d8eba52184f538c8a4525680cfb33.xyz/ Challenge-2 http://759d8eba52184f538c8a4525680cfb33.xyz/ http://759d8eba52184f538c8a4525680cfb33.xyz/
- jennymesika 7y agohttp://35.237.60.51 http://35.237.60.51
- Mossad14 7y ago35.246.158.51
- RetardedD 7y agohttps://dev.missilesys.com/ https://dev.missilesys.com/
- Harible 7y agoStill stuck at Level 2... Any ideas?
- yanirta 7y agoChallenge #2, someone forgot a reference to https://dev.missilesys.com/ https://dev.missilesys.com/ ;)
- yanirta 7y agoDo you experience timeouts and failures in https://dev.missilesys.com/ https://dev.missilesys.com/? Do you think it is intentional?
- zuburking 7y agois challenge 2 download cert page down?
- yanirta 7y agoHey, challenge #1 when used with https, https://3d375032374147a7865753e4bbc92682.xyz/ https://3d375032374147a7865753e4bbc92682.xyz/ Gets you the certificate of Challange #2, a shortcut? perhaps, or nothing is perfect???
- qwerty40 7y agoChallenge 3: Do we need to RE the EXE cause that’s look obvious but I don’t think that that’s what we need to do