
Showing posts from May, 2023

THM Writeup: TheValley

TheValley Recon A simple Rustscan shows us that there are 3 ports open.       We see that port 22 is for SSH, port 80 is for the web server, and port 37378 is for FTP based on the version scan from NMAP: Trying to connect to the FTP server results in nothing. So we start looking on the web server. Initial Foothold We run Gobuster, and find the following directories: all of which we look around but don't notice anything interesting off the bat (using both ZAP and viewing the source code). However, we find something interesting when we run Gobuster on one directory lower (on the /static directory). So we go to `/00` and find that it has a note: so we navigate to the directory /dev1243224123123  and find a login page and viewing the source page, we see the login username and password in the dev.js script! Logging in, it says that the credentials are re-used with FTP. So we take the same credentials and use it for FTP: and we transfer those files to our computer for furt...

The latest meme in Taiwan - 雞胸男

雞胸男 - The chicken breast man I'm currently in Taiwan on vacation - and what I've seen on the news is a great display of what news in Taiwan is all about. Let me explain why Taiwanese news is very different from the news I see in North America. In Taiwan, news channels obviously talk about current events. The political stuff, the sad stuff, and the dangerous stuff. But there's one key distinction in Taiwanese news compared with the regular news I watch in Canada - and that is in storytelling. You see, in Taiwan, it doesn't matter what kind of news you get. The reporters tell it like a story kind of like you're watching a reality TV show. For example, with traffic accidents, you get real traffic footage of how an accident unfolded. When you see disputes in a convenience store, 8 hours later some reporter has obtained the CCTV footage from the store owners. It makes it such that news reporting is covered so in-depth that you get detailed explanations of events that onl...