<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
>
<channel xml:lang="fr">
<title>Root Me : plateforme d'apprentissage d&#233;di&#233;e au Hacking et &#224; la S&#233;curit&#233; de l'Information</title>
<link>https://www.root-me.org/</link>
<description>Root Me est une plateforme permettant &#224; chacun de tester et d'am&#233;liorer ses connaissances dans le domaine de la s&#233;curit&#233; informatique et du hacking &#224; travers la publication de challenges, de solutions, d'articles.</description>
<language>fr</language>
<generator>SPIP - www.spip.net</generator>
<image>
<title>Root Me : plateforme d'apprentissage d&#233;di&#233;e au Hacking et &#224; la S&#233;curit&#233; de l'Information</title>
<url>https://www.root-me.org/local/cache-vignettes/L144xH144/siteon0-9a1b1.svg?1757799377</url>
<link>https://www.root-me.org/</link>
<height>144</height>
<width>144</width>
</image>
<item xml:lang="fr">
<title>Deep learning - Mod&#232;le malveillant</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/Deep-learning-Modele-malveillant</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/Deep-learning-Modele-malveillant</guid>
<dc:date>2024-07-26T18:32:45Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
blackndoor
</dc:creator>
<dc:subject>Difficile</dc:subject>
<description>
&lt;p&gt;Il ne faut JAMAIS charger un mod&#232;le t&#233;l&#233;charg&#233; sans avoir au pr&#233;alable effectu&#233; quelques v&#233;rifications. Le site suivant semble effectuer celles-ci avant de les charger, mais des sous-processus peuvent peut-&#234;tre s'ex&#233;cuter ?&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>Python - Eval Is Evil</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/Python-Eval-Is-Evil</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/Python-Eval-Is-Evil</guid>
<dc:date>2023-12-28T09:58:21Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
Mr7F
</dc:creator>
<dc:subject>Difficile</dc:subject>
<description>
&lt;p&gt;Echappez-vous de la cage con&#231;ue par un d&#233;veloppeur tr&#232;s pointilleux pour obtenir un shell&#160;!&lt;br class=&#034;autobr&#034; /&gt;
Dans sa grande bont&#233;, il vous a tout de m&#234;me fourni le code-source de la sandbox&#160;:&lt;/p&gt;
&lt;div class=&#034;coloration_code cadre&#034;&gt;&lt;div class=&#034;spip_python cadre&#034;&gt;&lt;div class=&#034;python&#034;&gt;&lt;ol&gt;&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span style=&#034;color: #808080; font-style: italic;&#034;&gt;#!/usr/bin/env python3&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;def&lt;/span&gt; say_hello&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;print&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;Hello&#034;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;def&lt;/span&gt; check_code&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;if&lt;/span&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;__&#034;&lt;/span&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;in&lt;/span&gt; &lt;span style=&#034;color: #008000;&#034;&gt;str&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt;.&lt;span style=&#034;color: black;&#034;&gt;co_names&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;raise&lt;/span&gt; &lt;span style=&#034;color: #008000;&#034;&gt;Exception&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;Try again&#034;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;for&lt;/span&gt; const &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;in&lt;/span&gt; &lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt;.&lt;span style=&#034;color: black;&#034;&gt;co_consts&lt;/span&gt;:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;if&lt;/span&gt; &lt;span style=&#034;color: #008000;&#034;&gt;hasattr&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;const&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;co_names&#034;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; check_code&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;const&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;BUILTINS &lt;span style=&#034;color: #66cc66;&#034;&gt;=&lt;/span&gt; &lt;span style=&#034;color: black;&#034;&gt;&#123;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;str&#034;&lt;/span&gt;: &lt;span style=&#034;color: #008000;&#034;&gt;str&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;int&#034;&lt;/span&gt;: &lt;span style=&#034;color: #008000;&#034;&gt;int&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;bool&#034;&lt;/span&gt;: &lt;span style=&#034;color: #008000;&#034;&gt;bool&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;bytes&#034;&lt;/span&gt;: &lt;span style=&#034;color: #dc143c;&#034;&gt;bytes&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;type&#034;&lt;/span&gt;: &lt;span style=&#034;color: #008000;&#034;&gt;type&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;Exception&#034;&lt;/span&gt;: &lt;span style=&#034;color: #008000;&#034;&gt;Exception&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;isinstance&#034;&lt;/span&gt;: &lt;span style=&#034;color: #008000;&#034;&gt;isinstance&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;print&#034;&lt;/span&gt;: &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;print&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;say_hello&#034;&lt;/span&gt;: say_hello&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;__import__&#034;&lt;/span&gt;: &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;lambda&lt;/span&gt; *a&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt; **kw: &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;print&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;Can not import !&#034;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span style=&#034;color: black;&#034;&gt;&#125;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;def&lt;/span&gt; sandbox&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt; &lt;span style=&#034;color: #66cc66;&#034;&gt;=&lt;/span&gt; &lt;span style=&#034;color: #008000;&#034;&gt;compile&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt;.&lt;span style=&#034;color: black;&#034;&gt;strip&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;&#034;&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;exec&#034;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; check_code&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #008000;&#034;&gt;eval&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt; &lt;span style=&#034;color: black;&#034;&gt;&#123;&lt;/span&gt;&lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;__builtins__&#034;&lt;/span&gt;: BUILTINS&lt;span style=&#034;color: black;&#034;&gt;&#125;&lt;/span&gt;&lt;span style=&#034;color: #66cc66;&#034;&gt;,&lt;/span&gt; &lt;span style=&#034;color: black;&#034;&gt;&#123;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&#125;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt; &lt;span style=&#034;color: #66cc66;&#034;&gt;=&lt;/span&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;&#034;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;while&lt;/span&gt; &lt;span style=&#034;color: #008000;&#034;&gt;True&lt;/span&gt;:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; line &lt;span style=&#034;color: #66cc66;&#034;&gt;=&lt;/span&gt; &lt;span style=&#034;color: #008000;&#034;&gt;input&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;&gt;&gt;&gt; &#034;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt; +&lt;span style=&#034;color: #66cc66;&#034;&gt;=&lt;/span&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034; &lt;span style=&#034;color: #000099; font-weight: bold;&#034;&gt;\n&lt;/span&gt;&#034;&lt;/span&gt; + line&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;while&lt;/span&gt; line:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; line &lt;span style=&#034;color: #66cc66;&#034;&gt;=&lt;/span&gt; &lt;span style=&#034;color: #008000;&#034;&gt;input&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;&#034;&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt; +&lt;span style=&#034;color: #66cc66;&#034;&gt;=&lt;/span&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034; &lt;span style=&#034;color: #000099; font-weight: bold;&#034;&gt;\n&lt;/span&gt;&#034;&lt;/span&gt; + line&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;try&lt;/span&gt;:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; sandbox&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;&lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;except&lt;/span&gt; &lt;span style=&#034;color: #008000;&#034;&gt;Exception&lt;/span&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;as&lt;/span&gt; e:&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #ff7700;font-weight:bold;&#034;&gt;print&lt;/span&gt;&lt;span style=&#034;color: black;&#034;&gt;&amp;#40;&lt;/span&gt;e&lt;span style=&#034;color: black;&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;span style=&#034;color: #dc143c;&#034;&gt;code&lt;/span&gt; &lt;span style=&#034;color: #66cc66;&#034;&gt;=&lt;/span&gt; &lt;span style=&#034;color: #483d8b;&#034;&gt;&#034;&#034;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;&lt;/div&gt;&lt;p class='download cadre_download'&gt;&lt;a href='https://www.root-me.org/local/cache-code/30b1d29b9b3f2941fb89ed5a93185e58.txt'&gt;T&#233;l&#233;charger&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge02.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;SSH&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;2222&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge02.root-me.org:2222&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2222 -ch@challenge02.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge02&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>R : ex&#233;cution de code</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/R-execution-de-code</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/R-execution-de-code</guid>
<dc:date>2023-09-25T10:47:58Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
Fey
</dc:creator>
<dc:subject>Facile</dc:subject>
<description>
&lt;p&gt;Vos examens d'analyses statistiques en R approchent.&lt;br class=&#034;autobr&#034; /&gt;
Votre professeur a mis &#224; disposition sur l'ENT de la fac un interpreter R pour que vous puissiez vous exercer.&lt;br class=&#034;autobr&#034; /&gt;
Vous n'avez pas le temps de r&#233;viser, vous d&#233;cidez de d&#233;rober les sujets d'examens.&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>AppArmor - Jail Medium</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/AppArmor-Jail-Medium</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/AppArmor-Jail-Medium</guid>
<dc:date>2023-09-25T10:46:59Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
nivram
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;div class=&#034;warning&#034;&gt;
&lt;strong&gt;Attention&lt;/strong&gt;&#160;: ce challenge est disponible via la machine CTF-ATD &#034;AppArmorJail2&#034;. Il n'y a pas de fichier /passwd, il n'est donc pas possible de valider la machine sur le CTF-ATD.
&lt;/div&gt;
&lt;p&gt;L'administrateur n'est pas content, vous avez r&#233;ussi &#224; contourner sa pr&#233;c&#233;dente politique AppArmor. Il l'a donc am&#233;lior&#233;e afin que vous ne puissiez plus lire ses pr&#233;cieux secrets.&lt;/p&gt;
&lt;p&gt;Il est tellement s&#251;r de lui qu'il vous a laiss&#233; la configuration dans le but de vous narguer. Montrez lui que c'&#233;tait une mauvaise id&#233;e&#160;!&lt;/p&gt;
&lt;div class=&#034;coloration_code code&#034;&gt;&lt;div class=&#034;spip_ code&#034;&gt;&lt;div class=&#034;&#034;&gt;&lt;ol&gt;&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;#include &lt;tunables/global&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;profile docker_chall_medium flags=&lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;attach_disconnected,mediate_deleted&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt; &lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; #include &lt;abstractions/base&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; network,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; capability,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; file,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; umount,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; signal &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;send,receive&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny mount,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^f&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/f&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^c&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/c&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^g&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/cg&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^r&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/firmware/** rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/kernel/security/** rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/* w, # deny write for all files directly in /proc &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;not in a subdir&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; # deny write to files not in /proc/&lt;number&gt;/** or /proc/sys/**&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-9s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-9y&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-9s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/** w,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sys/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^k&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;** w, # deny /proc/sys except /proc/sys/k* &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;effectively /proc/sys/kernel&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sys/kernel/&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;?,??,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^h&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^m&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;**&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt; w, # deny everything except shm* in /proc/sys/kernel/&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sysrq-trigger rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/kcore rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; /usr/local/bin/sh px -&gt; shprof2,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /home/admin/** w,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /home/admin/flag_here/flag.txt r,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;profile shprof2 flags=&lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;attach_disconnected,mediate_deleted&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt; &lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; #include &lt;abstractions/base&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; #include &lt;abstractions/bash&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; network,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; capability,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; mount,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny mount cgroup, # prevent container escape&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; umount,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; file,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; signal &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;send,receive&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^f&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/f&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^c&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/c&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^g&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/cg&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^r&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/firmware/** rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/kernel/security/** rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/* w, # deny write for all files directly in /proc &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;not in a subdir&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; # deny write to files not in /proc/&lt;number&gt;/** or /proc/sys/**&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-9s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-9y&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-9s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/** w,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sys/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^k&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;** w, # deny /proc/sys except /proc/sys/k* &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;effectively /proc/sys/kernel&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sys/kernel/&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;?,??,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^h&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^m&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;**&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt; w, # deny everything except shm* in /proc/sys/kernel/&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sysrq-trigger rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/kcore rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; /lib/x86_64-linux-gnu/ld-*.so mr,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /home/admin/** w,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /home/admin/flag_here/flag.txt r,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;&lt;/div&gt;&lt;p class='download code_download'&gt;&lt;a href='https://www.root-me.org/local/cache-code/35a930c411d223cfa38013f6ed26b7ab.txt'&gt;T&#233;l&#233;charger&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;ul class=&#034;spip&#034;&gt;&lt;li&gt; D&#233;marrez le CTF-ATD &#034;AppArmorJail2&#034;&lt;/li&gt;&lt;li&gt; Connectez-vous en SSH sur la machine port 22222 (admin:admin)&lt;/li&gt;&lt;li&gt; Le mot de passe de validation du challenge est dans le fichier /home/admin/flag_here/flag.txt&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;N'h&#233;sitez pas &#224; changer le mot de passe de l'utilisateur admin afin d'&#234;tre seul sur la machine pour r&#233;aliser vos manipulations&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt; &lt;a class=&#034;button small radius&#034; target=&#034;_BLANK&#034; href='https://www.root-me.org/?page=start_ctf_alltheday&amp;#38;id_environnement_virtuel=280&amp;#38;lang=fr' &gt;D&#233;marrer le CTF all the day&lt;/a&gt;&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>AppArmor - Jail Introduction</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/AppArmor-Jail-Introduction</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/AppArmor-Jail-Introduction</guid>
<dc:date>2023-05-10T13:00:54Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
nivram
</dc:creator>
<dc:subject>Facile</dc:subject>
<description>
&lt;div class=&#034;warning&#034;&gt;
&lt;strong&gt;Attention&lt;/strong&gt;&#160;: ce challenge est disponible via la machine CTF-ATD &#034;AppArmorJail1&#034;. Il n'y a pas de fichier /passwd, il n'est donc pas possible de valider la machine sur le CTF-ATD.
&lt;/div&gt;
&lt;p&gt;Lors de la connexion au serveur de l'administrateur, un shell restreint via une politique AppArmor vous emp&#234;che de lire le flag bien que vous en soyez le propri&#233;taire...&lt;/p&gt;
&lt;p&gt;Trouvez un moyen de lire le flag &#224; tout prix et passez outre la politique AppArmor mise en place dont voici la configuration&#160;:&lt;/p&gt;
&lt;div class=&#034;coloration_code code&#034;&gt;&lt;div class=&#034;spip_ code&#034;&gt;&lt;div class=&#034;&#034;&gt;&lt;ol&gt;&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;#include &lt;tunables/global&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;profile docker_chall01 flags=&lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;attach_disconnected,mediate_deleted&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt; &lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; #include &lt;abstractions/base&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; network,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; capability,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; file,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; umount,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; signal &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;send,receive&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny mount,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^f&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/f&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^c&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/c&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^g&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/cg&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^r&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/firmware/** rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/kernel/security/** rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/* w, # deny write for all files directly in /proc &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;not in a subdir&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; # deny write to files not in /proc/&lt;number&gt;/** or /proc/sys/**&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-9s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-9y&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-9s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/** w,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sys/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^k&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;** w, # deny /proc/sys except /proc/sys/k* &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;effectively /proc/sys/kernel&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sys/kernel/&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;?,??,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^h&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^m&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;**&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt; w, # deny everything except shm* in /proc/sys/kernel/&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sysrq-trigger rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/kcore rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; /home/app-script-ch27/bash px -&gt; bashprof1,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;profile bashprof1 flags=&lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;attach_disconnected,mediate_deleted&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt; &lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; #include &lt;abstractions/base&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; #include &lt;abstractions/bash&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; network,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; capability,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny mount,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; umount,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; signal &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;send,receive&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^f&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/f&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^c&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/c&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^g&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/fs/cg&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^r&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*/** wklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/firmware/** rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /sys/kernel/security/** rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/* w, # deny write for all files directly in /proc &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;not in a subdir&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; # deny write to files not in /proc/&lt;number&gt;/** or /proc/sys/**&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-9s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-9y&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-9s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;1&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^&lt;span style=&#034;&#034;&gt;0&lt;/span&gt;-&lt;span style=&#034;&#034;&gt;9&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;*&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/** w,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sys/&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^k&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;** w, # deny /proc/sys except /proc/sys/k* &lt;span class=&#034;br0&#034;&gt;&amp;#40;&lt;/span&gt;effectively /proc/sys/kernel&lt;span class=&#034;br0&#034;&gt;&amp;#41;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sys/kernel/&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;?,??,&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^s&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^h&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;&lt;span class=&#034;br0&#034;&gt;&amp;#91;&lt;/span&gt;^m&lt;span class=&#034;br0&#034;&gt;&amp;#93;&lt;/span&gt;**&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt; w, # deny everything except shm* in /proc/sys/kernel/&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/sysrq-trigger rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny @&lt;span class=&#034;br0&#034;&gt;&#123;&lt;/span&gt;PROC&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;/kcore rwklx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; &lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; / r,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; /** mrwlk,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; /bin/** ix,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; /usr/bin/** ix,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; /lib/x86_64-linux-gnu/ld-*.so mrUx,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt; deny /home/app-script-ch27/flag.txt r,&lt;/div&gt;&lt;/li&gt;
&lt;li style=&#034;font-weight: normal; vertical-align:top;&#034;&gt;&lt;div style=&#034;&#034;&gt;&lt;span class=&#034;br0&#034;&gt;&#125;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;&lt;/div&gt;&lt;p class='download code_download'&gt;&lt;a href='https://www.root-me.org/local/cache-code/b12701cb7590db0f79cbcfccb5a72de5.txt'&gt;T&#233;l&#233;charger&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;ul class=&#034;spip&#034;&gt;&lt;li&gt; D&#233;marrez le CTF-ATD &#034;AppArmorJail1&#034;&lt;/li&gt;&lt;li&gt; Connectez-vous en SSH sur la machine port 22222 (app-script-ch27:app-script-ch27)&lt;/li&gt;&lt;li&gt; Le mot de passe de validation du challenge est dans le fichier /home/app-script-ch27/flag.txt&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;N'h&#233;sitez pas &#224; changer le mot de passe de l'utilisateur app-script-ch27 afin d'&#234;tre seul sur la machine pour r&#233;aliser vos manipulations&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt; &lt;a class=&#034;button small radius&#034; target=&#034;_BLANK&#034; href='https://www.root-me.org/?page=start_ctf_alltheday&amp;#38;id_environnement_virtuel=270&amp;#38;lang=fr' &gt;D&#233;marrer le CTF all the day&lt;/a&gt;&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>Docker - Talk through me</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/Docker-Talk-through-me</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/Docker-Talk-through-me</guid>
<dc:date>2022-02-24T19:25:48Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
Nishacid
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;Maintenant que vous avez d&#233;montr&#233; &#224; l'administrateur syst&#232;me que ses containers n'&#233;taient pas s&#233;curis&#233;s, il vous demande donc de vous connecter pour tester la s&#233;curit&#233; de son nouveau container pendant qu'il en d&#233;ploie un second.&lt;/p&gt;
&lt;ul class=&#034;spip&#034;&gt;&lt;li&gt; D&#233;marrez le CTF-ATD &#034;Talk through me&#034;&lt;/li&gt;&lt;li&gt; Connectez-vous en SSH sur le docker de la machine port 2222 (root / JL&amp;g#4zNkQ&amp;ztF8b)&lt;/li&gt;&lt;li&gt; Le mot de passe de validation du challenge est dans le fichier .passwd&lt;/li&gt;&lt;li&gt; Le mot de passe de validation du CTF-ATD est dans le fichier /passwd&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt; &lt;a class=&#034;button small radius&#034; target=&#034;_BLANK&#034; href='https://www.root-me.org/?page=start_ctf_alltheday&amp;#38;id_environnement_virtuel=%20223&amp;#38;lang=fr' &gt;D&#233;marrer le CTF all the day&lt;/a&gt;&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>Docker - Sys-Admin's Docker</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/Docker-Sys-Admin-s-Docker</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/Docker-Sys-Admin-s-Docker</guid>
<dc:date>2022-02-24T19:25:39Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
Nishacid
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;Vous avez prouv&#233; a cet administrateur qu'il n'arrive pas &#224; se renseigner sur comment s&#233;curiser un container, il est fou de rage et met en place des mesures de s&#233;curit&#233; suppl&#233;mentaires.&lt;/p&gt;
&lt;ul class=&#034;spip&#034;&gt;&lt;li&gt; D&#233;marrez le CTF-ATD &#034;Sys-Admin's Docker&#034;&lt;/li&gt;&lt;li&gt; Connectez-vous en SSH sur le docker de la machine port 2222&#160;:&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;&lt;code class='spip_code' dir='ltr'&gt;root:&amp;h?rHjb6z#h8&amp;gYx&lt;/code&gt;&lt;/p&gt;
&lt;ul class=&#034;spip&#034;&gt;&lt;li&gt; Le mot de passe de validation du challenge est dans le fichier .passwd&lt;/li&gt;&lt;li&gt; Le mot de passe de validation du CTF-ATD est dans le fichier /passwd&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt; &lt;a class=&#034;button small radius&#034; target=&#034;_BLANK&#034; href='https://www.root-me.org/?page=start_ctf_alltheday&amp;#38;id_environnement_virtuel=222&amp;#38;lang=fr' &gt;D&#233;marrer le CTF all the day&lt;/a&gt;&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>Docker - I am groot</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/Docker-I-am-groot</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/Docker-I-am-groot</guid>
<dc:date>2022-02-24T19:25:25Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
Nishacid
</dc:creator>
<dc:subject>Facile</dc:subject>
<description>
&lt;p&gt;L'un des administrateurs syst&#232;me d&#233;ploie une machine docker en root et avec des privil&#232;ges, il vous dit que ce n'est pas important car, tant que c'est dans le container, c'est s&#233;curis&#233;&#160;:)&lt;/p&gt;
&lt;ul class=&#034;spip&#034;&gt;&lt;li&gt; D&#233;marrez le CTF-ATD &#034;I am groot&#034;&lt;/li&gt;&lt;li&gt; Connectez-vous en SSH sur le docker de la machine port 2222 (root / arq87TNDCf9NfksD)&lt;/li&gt;&lt;li&gt; Le mot de passe de validation du challenge est dans le fichier .passwd&lt;/li&gt;&lt;li&gt; Le mot de passe de validation du CTF-ATD est dans le fichier /passwd&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt; &lt;a class=&#034;button small radius&#034; target=&#034;_BLANK&#034; href='https://www.root-me.org/?page=start_ctf_alltheday&amp;#38;id_environnement_virtuel=217&amp;#38;lang=fr' &gt;D&#233;marrer le CTF all the day&lt;/a&gt;&lt;/p&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>Python - format string</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/Python-format-string</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/Python-format-string</guid>
<dc:date>2021-03-26T06:32:48Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
lovasoa
</dc:creator>
<dc:subject>Moyen</dc:subject>
<description>
&lt;p&gt;Identifiez la faille dans le script suivant pour extraire le mot de passe validation&#160;:&lt;/p&gt;
&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge02.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;SSH&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;2222&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge02.root-me.org:2222&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2222 -ch@challenge02.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge02&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
<item xml:lang="fr">
<title>LaTeX - Execution de commandes</title>
<link>https://www.root-me.org/fr/Challenges/App-Script/LaTeX-Execution-de-commandes</link>
<guid isPermaLink="true">https://www.root-me.org/fr/Challenges/App-Script/LaTeX-Execution-de-commandes</guid>
<dc:date>2021-03-17T09:07:53Z</dc:date>
<dc:format>text/html</dc:format>
<dc:language>fr</dc:language>
<dc:creator>
Podalirius
, 
Mhd_Root
</dc:creator>
<dc:subject>Facile</dc:subject>
<description>
&lt;p&gt;Ex&#233;cutez des commandes pour trouver le flag&#160;!&lt;/p&gt;
&lt;h5&gt;Param&#232;tres de connexion au challenge&lt;/h5&gt; &lt;table class=&#034;txs mauto&#034; style=&#034;width: 100%&#034;&gt; &lt;tbody&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;H&#244;te&lt;/td&gt;&lt;td&gt;challenge02.root-me.org&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Protocole&lt;/td&gt;&lt;td&gt;SSH&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Port&lt;/td&gt;&lt;td&gt;2222&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt; &lt;td&gt;Acc&#232;s SSH&lt;/td&gt; &lt;td&gt; &lt;a href=&#034;ssh://-ch:-ch@challenge02.root-me.org:2222&#034; title=&#034;Acc&#232;s SSH&#034;&gt;ssh -p 2222 -ch@challenge02.root-me.org&lt;/a&gt; &lt;a target=&#034;_blank&#034; href=&#034;http://webssh.root-me.org/?location=WebSSH_&amp;ssh=ssh://-ch:-ch@challenge02&#034; title=&#034;WebSSH&#034;&gt;&lt;img src='https://www.root-me.org/squelettes/img/webssh.png?1454749832' alt='' width='16' height='14' /&gt; WebSSH&lt;/a&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr class=&#034;row_odd&#034;&gt;&lt;td&gt;Nom d'utilisateur&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;tr class=&#034;row_even&#034;&gt;&lt;td&gt;Mot de passe&lt;/td&gt;&lt;td&gt;-ch&lt;/td&gt;&lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;br/&gt;
-
&lt;a href="https://www.root-me.org/fr/Challenges/App-Script/" rel="directory"&gt;App - Script&lt;/a&gt;
</description>
</item>
</channel>
</rss>
