Author: adm_synoslabs

  • Cody Bernardy – Challenge 06

    One of my favourite challenge of this series. It requires to analyze elements in the video and not just only perform reverse image search (which doesn’t work here). Link to the OSINT challenge video: https://www.youtube.com/watch?v=l0OeSW6QifE I urge you to try by yourself before looking at this solution Solution As explained in the excerpt, this challenge…

    Lire plus: Cody Bernardy – Challenge 06
  • Cody Bernardy – Challenge 05

    This challenge was one of the toughest from this series of challenges proposed by Cody Bernardy. A very few pieces of information are given during the video, so we must focus on the correct ones. Link to the OSINT challenge video: https://www.youtube.com/watch?v=Hxp5uLV7AD8 I urge you to try by yourself before looking at this solution Solution…

    Lire plus: Cody Bernardy – Challenge 05
  • Cody Bernardy – Challenge 04

    This challenge can be solved in multiple ways. We’ll only focus on the fastest one but I encourage you to do it on your own. Link to the OSINT challenge video: https://www.youtube.com/watch?v=yv1gRPQcGhE I urge you to try by yourself before looking at this solution Solution As always when we try to solve this type of…

    Lire plus: Cody Bernardy – Challenge 04
  • Cody Bernardy – Challenge 03

    This easy challenge will be solved using reverse image search and shows the power of such tools in investigations to identify objects and recognizable items on a photo. Link to the OSINT challenge video: https://www.youtube.com/watch?v=c4q7XrAy5g4 I urge you to try by yourself before looking at this solution Solution We wont lost any time and directly…

    Lire plus: Cody Bernardy – Challenge 03
  • Cody Bernardy – Challenge 01

    In this first challenge, our goal is to geolocate where the video was recorded. A lot of elements are given directly by Cody but we’ll try to resolve this challenge without the hints he gives. Link to the OSINT challenge video: https://www.youtube.com/watch?v=f7mpY674ZvA I urge you to try by yourself before looking at this solution Solution…

    Lire plus: Cody Bernardy – Challenge 01
  • Méthodologie GEOINT par l’exemple

    Faut-il être un expert en informatique, savoir coder et être ultra intelligent pour faire de l’OSINT/GEOINT et résoudre des challenges ? Spoiler : non. Une simple méthodologie et une grande curiosité sont généralement nécessaires. Aujourd’hui je vous montre un exemple concret de géolocalisation en n’utilisant que l’OSINT sans jamais faire de recherche d’image inversée. Et…

    Lire plus: Méthodologie GEOINT par l’exemple
  • Une backdoor découverte dans XZ Utils (CVE-2024-3094)

    Ce vendredi 29 mars 2024, un certain Andres Freund a découvert une backdoor dans la suite XZ Utils. Cela nous rappelle la backdoor qui avait été injectée dans PHP (https://flast101.github.io/php-8.1.0-dev-backdoor-rce/) ou même encore la très connue version 2.3.4 de vsftpd dans laquelle on pouvait également exécuter des commandes sans avoir besoin de s’authentifier sur la…

    Lire plus: Une backdoor découverte dans XZ Utils (CVE-2024-3094)
  • 💻 Mirai – Writeup

    Default credentials we’ll be used on this machine to access it. Add the IP address in /etc/hosts: … 10.10.10.48 mirai.htb … First run a nmap scan: A lot of ports are open contrary to the other easy boxes. Let’s start with the website: It tells us that the machine is a Pi-hole version 3.1.4. We…

    Lire plus: 💻 Mirai – Writeup
  • 💻 Legacy – Writeup

    We’ll use a very famous CVE vulnerability to exploit this machine. Add the IP address in /etc/hosts: … 10.10.10.4 legacy.htb … First run a nmap scan: Only 2 ports seem interesting: 139 and 445 which are SMB ports. We can run some enumeration on them: We got some data but nothing really useful. smbclientdoesn’t return…

    Lire plus: 💻 Legacy – Writeup