> For the complete documentation index, see [llms.txt](https://szczygielka.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://szczygielka.gitbook.io/writeups/ctfs-writeups/0xl4ugh-ctf-2024/wordpress-2-forensics.md).

# Wordpress - 2 - Forensics

## Task

Q1. During enumeration, the attacker tried to identify users on the site. List all the users that the attacker enumerated. (seperate them with :),(sort them by alphapitical order)

Q2. After enumeration, a brute force attack was launched against all users. The attacker successfully gained access to one of the accounts. What are the username and password for that account, and what is the name of the page used for the brute force attack?

Flag Format: **0xL4ugh{A1\_A2}**

Example: 0xL4ugh{username1:username2\_username:password\_pageName.ext}

## Solution

From the content of `WordPress - 1` task we know that the WordPress website had a security breach. In the `WordPress 1` task, I determined the IP address of the victim, i.e. `192.168.204.128` and the IP addresses of both attackers: `192.168.204.132` and `192.168.204.1`.  This knowledge will be useful to us in solving this task.&#x20;

We will filter the results to receive all `POST` HTTP requests sent to the IP address `192.168.204.128`. We can see that at least several login attempts were made from the IP address `192.168.204.132` belonging to one of the attackers. The attacker tried to log in as:

1. user `not7amoksha`:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FOpjPyK6tmxsZbEBxzLXF%2Fimage.png?alt=media&amp;token=7c70a0cb-7d29-4b0e-a5c2-b4e65b93defc" alt=""><figcaption></figcaption></figure>

2. user `a1l4m`:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FvfW8F6XUgmXCr9rAoZ8B%2Fimage.png?alt=media&amp;token=a3bb5251-afb8-411e-97be-73d88e4b76b4" alt=""><figcaption></figcaption></figure>

3. user `demomorgan`:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FRKsmXup3TrXiNgFu8Osm%2Fimage.png?alt=media&amp;token=990771d0-65ed-4b64-81fa-695aca1d4b0d" alt=""><figcaption></figcaption></figure>

After filtering for HTTP traffic we can see that the attacker enumerated the values of the `author` variable:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2Flsb1mGHU26zhRe0xFDzg%2Fimage.png?alt=media&amp;token=3c714dae-85e2-474a-8c9e-1e1048e79f7a" alt=""><figcaption></figcaption></figure>

Let's examine the HTTP stream for the selected package number `88288`. By following the HTTP stream to get queries about the author with a given number, we can see that for queries with index 1 and 2, the response `301 Moved Pernamently` is returned. Additionally, `GET` `/wordpress/author/<user>` queries for users `a1l4m` and `not7amoksha` returned responses `200 OK`, which proves that such authors exist:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FHqZVPJKuEQUHOknMo4Yt%2Fimage.png?alt=media&amp;token=f74437db-c6c0-4c43-b0fc-41facde2559e" alt="" width="375"><figcaption></figcaption></figure>

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FqmKeVWWj6iDNqYvpaBie%2Fimage.png?alt=media&amp;token=a60b8094-d4de-49b4-a64a-b69cd3ba923b" alt="" width="375"><figcaption></figcaption></figure>

In the same HTTP stream, we can notice that a request for an author with index 3 returns a response `200 OK`. In the content of the response, we can see information proving that the third user is `demomorgan`:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FOULJwY83qWOHpHfjtqTs%2Fimage.png?alt=media&amp;token=c437087d-1da9-476c-b66d-d203a2fc3885" alt="" width="563"><figcaption></figcaption></figure>

Sorted 3 users alphabetically:

```
a1l4m demomorgan not7amoksha
```

Now let's look for more information about the brute force attack carried out. After filtering the results for the HTTP `POST` method, we can see that almost all queries were sent to `/wordpress/xmlrpc.php`:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FGue6dIDC7SdF1a4M1ESz%2Fimage.png?alt=media&amp;token=4051d0fe-3dfb-48d6-8a45-543883ce089c" alt=""><figcaption></figcaption></figure>

The time between individual HTTP requests is small, which also indicates the brute force attack. So the webpage used to brute force attack is:

```
xmlrpc.php
```

If the attacker was searching for users on the website, he certainly wanted to use usernames to conduct a brute force attack. So let's search in packet details strings containing names of users.&#x20;

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FQCWSsOxHiQOy52RbXHJP%2Fimage.png?alt=media&amp;token=7705244f-89c5-4eab-bebb-564aa5150e70" alt=""><figcaption></figcaption></figure>

Let's check the contents of the example `POST` request along with the response for the query that might contain an attempt to force a password for the user `a1l4m`:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FXBHMVNHAvxx5486J7I4c%2Fimage.png?alt=media&amp;token=2f7be274-cca9-4c19-a8ee-be8ea5a7038c" alt="" width="563"><figcaption></figcaption></figure>

Based on the response received this looks like a failed login attempt. The remaining responses to failed login attempts are as follows:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FMtsTBPSOrT7D2tkw6zFl%2Fimage.png?alt=media&amp;token=45962b0a-9e72-4d80-b08f-c4fa835be57c" alt=""><figcaption></figcaption></figure>

Based on responses for invalid login attempts let's try to exclude all responses that have a length 674. After excluding we get 6 packets:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FNnzS31MAFgwwpjfq5qxZ%2Fimage.png?alt=media&amp;token=7087591a-e7d6-4789-a270-48594f6347e6" alt=""><figcaption></figcaption></figure>

In the last package, we found information that may indicate that the login was successful, i.e. the value of the `isAdmin` variable is set to `0`:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2FFopobLB7hj8RCQrVY1QV%2Fimage.png?alt=media&amp;token=8088f115-310c-4fa5-9b20-c0b896d499ae" alt=""><figcaption></figcaption></figure>

Let's follow the stream for this packet. In the `POST` request we can find credentials:

<figure><img src="https://1764482864-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsK05LA2NAjKs68dl8qHP%2Fuploads%2F82zgppk6cBHytLzNGeV6%2Fimage.png?alt=media&amp;token=81d167d0-f16a-42ea-bd6a-79d1d756ddf2" alt=""><figcaption></figcaption></figure>

The login details from the `POST` request are as follows:

```
demomorgan:demomorgan
```

We've gathered all the information you need to get your flag.&#x20;

Flag:

```
0xL4ugh{a1l4m:demomorgan:not7amoksha_demomorgan:demomorgan_xmlrpc.php}
```
