{"id":509,"date":"2020-09-23T10:18:21","date_gmt":"2020-09-23T10:18:21","guid":{"rendered":"https:\/\/www.unordnung.net\/?p=509"},"modified":"2020-09-23T10:18:21","modified_gmt":"2020-09-23T10:18:21","slug":"finally-brainfuck-a-thm-writeup-of-blobblog","status":"publish","type":"post","link":"https:\/\/unordnung.net\/misc\/2020\/09\/finally-brainfuck-a-thm-writeup-of-blobblog\/","title":{"rendered":"Finally Brainfuck, a THM writeup of BlobBlog"},"content":{"rendered":"\n<p>Well it was anno 1998 when an older friend showed me the brainfuck programing language and what I took from this evening was, that such creepy codes are what&#8217;s needed for getting into hacking. That made me stay away from really digging into hacking until 20 years later.<\/p>\n\n\n<p><code>+[---&gt;++&lt;]&gt;+.+++[-&gt;++++&lt;]&gt;.---.+++++++++.-[-&gt;+++++&lt;]&gt;-.++++[-&gt;++&lt;]&gt;+.-[-&gt;++++&lt;]&gt;.--[-&gt;++++&lt;]&gt;-.-[-&gt;+++&lt;]&gt;-.--[---&gt;+&lt;]&gt;--.+[----&gt;+&lt;]&gt;+++.[-&gt;+++&lt;]&gt;+.-[-&gt;+++&lt;]&gt;.-[---&gt;++&lt;]&gt;+.--.-----.[-&gt;+++&lt;]&gt;.------------.+[-----&gt;+&lt;]&gt;.--[---&gt;+&lt;]&gt;.-[----&gt;+&lt;]&gt;++.++[-&gt;+++&lt;]&gt;.++++++++++++.---------.----.+++++++++.----------.--[---&gt;+&lt;]&gt;---.+[----&gt;+&lt;]&gt;+++.[-&gt;+++&lt;]&gt;+.+++++++++++++.----------.-[---&gt;+&lt;]&gt;-.++++[-&gt;++&lt;]&gt;+.-[-&gt;++++&lt;]&gt;.--[-&gt;++++&lt;]&gt;-.--------.++++++.---------.--------.-[---&gt;+&lt;]&gt;-.[-&gt;+++&lt;]&gt;+.+++++++++++.+++++++++++.-[-&gt;+++&lt;]&gt;-.+[---&gt;+&lt;]&gt;+++.------.+[----&gt;+&lt;]&gt;+++.-[---&gt;++&lt;]&gt;+.+++.+.------------.++++++++.-[++&gt;---&lt;]&gt;+.+++++[-&gt;+++&lt;]&gt;.-.-[-&gt;+++++&lt;]&gt;-.++[--&gt;+++&lt;]&gt;.[---&gt;++&lt;]&gt;--.+++++[-&gt;+++&lt;]&gt;.---------.[---&gt;+&lt;]&gt;--.+++++[-&gt;+++&lt;]&gt;.++++++.---.[--&gt;+++++&lt;]&gt;+++.+[-----&gt;+&lt;]&gt;+.---------.++++.--.+.------.+++++++++++++.+++.+.+[----&gt;+&lt;]&gt;+++.+[-&gt;+++&lt;]&gt;+.+++++++++++..+++.+.+[++&gt;---&lt;]&gt;.++[---&gt;++&lt;]&gt;..[-&gt;++&lt;]&gt;+.[---&gt;+&lt;]&gt;+.+++++++++++.-[-&gt;+++&lt;]&gt;-.+[---&gt;+&lt;]&gt;+++.------.+[----&gt;+&lt;]&gt;+++.-[---&gt;++&lt;]&gt;--.+++++++.++++++.--.++++[-&gt;+++&lt;]&gt;.[---&gt;+&lt;]&gt;----.+[----&gt;+&lt;]&gt;+++.[--&gt;+++&lt;]&gt;+.-----.------------.---[-&gt;++++&lt;]&gt;.------------.---.+++++++++.-[-&gt;+++++&lt;]&gt;-.++[--&gt;+++&lt;]&gt;.-------.------------.---[-&gt;++++&lt;]&gt;.------------.---.+++++++++.-[-&gt;+++++&lt;]&gt;-.-----[-&gt;++&lt;]&gt;-.--[---&gt;++&lt;]&gt;-.<\/code><\/p>\n\n\n<p>It seems my trauma comes true, being a junior pentester for about a year now, i finally approached a challenge with brainfuck included. lol. Look at this cruelty of a code. I didn&#8217;t realize its brainfuck on first sight, but it made me feel an itch of hauntedness in the back of my head.<\/p>\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>When I was a kid, my friends and I would always knock on <s>n<\/s> of our neighbors doors. Always houses <s>n<\/s>, then <s>n<\/s>, then <s>n<\/s>!<\/p><cite>base64;brainfuck&#8217;ed; n is censored<\/cite><\/blockquote>\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow\">\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Dang it Bob, why do you always forget your password?<br \/>I&#8217;ll encode for you here so nobody else can figure out what it is:<br \/><s>Kjbbfeh378DHns<\/s><\/p><cite>html comment<\/cite><\/blockquote>\n\n\n<p>Looks like there&#8217;s a user Bob with a pw that encoded in some way, while text is probably a hint for it. I thought it had to be shift cipher with being n,n,n the shifts and every n char. but that failed and you can&#8217;t bruteforce, since you get banned for pw login after a few failures. brainfuckyou, huh?<\/p>\n\n\n<p>++++++++++[&gt;+&gt;+++&gt;+++++++&gt;++++++++++&lt;&lt;&lt;&lt;-]&gt;&gt;&gt;&gt;+++++.&lt;&lt;++.&gt;&gt;&#8212;.-..+++++++.&lt;&lt;.&gt;&gt;++++++++.&#8211;.&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;.++++++++++++++++++++.&#8212;&#8212;&#8211;.&#8212;&#8212;&#8212;&#8212;.+++++++++++++++++++.&#8212;&#8212;&#8212;&#8211;.&#8212;&#8212;.&#8211;.+++++++++++..+++++++++++++.&lt;&lt;.&gt;&gt;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;.++++++++++++++++.&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;.++++++++.+++++.&#8212;&#8212;&#8211;.+++++++++++++++.&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;.++++++++.&#8212;&#8212;.-.<\/p>\n\n\n<p>tbc&#8230;unfortunately there&#8217;s a lot of personal trouble going on in my life right now, so might take a while.<\/p>\n<\/div><\/div>\n\n\n<p>BTW i love <a href=\"https:\/\/www.dcode.fr\">dcode.fr<\/a> &lt;3<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Well it was anno 1998 when an older friend showed me the brainfuck programing language and what I took from this evening was, that such creepy codes are what&#8217;s needed for getting into hacking. That made me stay away from really digging into hacking until 20 years later. +[&#8212;&gt;++&lt;]&gt;+.+++[-&gt;++++&lt;]&gt;.&#8212;.+++++++++.-[-&gt;+++++&lt;]&gt;-.++++[-&gt;++&lt;]&gt;+.-[-&gt;++++&lt;]&gt;.&#8211;[-&gt;++++&lt;]&gt;-.-[-&gt;+++&lt;]&gt;-.&#8211;[&#8212;&gt;+&lt;]&gt;&#8211;.+[&#8212;-&gt;+&lt;]&gt;+++.[-&gt;+++&lt;]&gt;+.-[-&gt;+++&lt;]&gt;.-[&#8212;&gt;++&lt;]&gt;+.&#8211;.&#8212;&#8211;.[-&gt;+++&lt;]&gt;.&#8212;&#8212;&#8212;&#8212;.+[&#8212;&#8211;&gt;+&lt;]&gt;.&#8211;[&#8212;&gt;+&lt;]&gt;.-[&#8212;-&gt;+&lt;]&gt;++.++[-&gt;+++&lt;]&gt;.++++++++++++.&#8212;&#8212;&#8212;.&#8212;-.+++++++++.&#8212;&#8212;&#8212;-.&#8211;[&#8212;&gt;+&lt;]&gt;&#8212;.+[&#8212;-&gt;+&lt;]&gt;+++.[-&gt;+++&lt;]&gt;+.+++++++++++++.&#8212;&#8212;&#8212;-.-[&#8212;&gt;+&lt;]&gt;-.++++[-&gt;++&lt;]&gt;+.-[-&gt;++++&lt;]&gt;.&#8211;[-&gt;++++&lt;]&gt;-.&#8212;&#8212;&#8211;.++++++.&#8212;&#8212;&#8212;.&#8212;&#8212;&#8211;.-[&#8212;&gt;+&lt;]&gt;-.[-&gt;+++&lt;]&gt;+.+++++++++++.+++++++++++.-[-&gt;+++&lt;]&gt;-.+[&#8212;&gt;+&lt;]&gt;+++.&#8212;&#8212;.+[&#8212;-&gt;+&lt;]&gt;+++.-[&#8212;&gt;++&lt;]&gt;+.+++.+.&#8212;&#8212;&#8212;&#8212;.++++++++.-[++&gt;&#8212;&lt;]&gt;+.+++++[-&gt;+++&lt;]&gt;.-.-[-&gt;+++++&lt;]&gt;-.++[&#8211;&gt;+++&lt;]&gt;.[&#8212;&gt;++&lt;]&gt;&#8211;.+++++[-&gt;+++&lt;]&gt;.&#8212;&#8212;&#8212;.[&#8212;&gt;+&lt;]&gt;&#8211;.+++++[-&gt;+++&lt;]&gt;.++++++.&#8212;.[&#8211;&gt;+++++&lt;]&gt;+++.+[&#8212;&#8211;&gt;+&lt;]&gt;+.&#8212;&#8212;&#8212;.++++.&#8211;.+.&#8212;&#8212;.+++++++++++++.+++.+.+[&#8212;-&gt;+&lt;]&gt;+++.+[-&gt;+++&lt;]&gt;+.+++++++++++..+++.+.+[++&gt;&#8212;&lt;]&gt;.++[&#8212;&gt;++&lt;]&gt;..[-&gt;++&lt;]&gt;+.[&#8212;&gt;+&lt;]&gt;+.+++++++++++.-[-&gt;+++&lt;]&gt;-.+[&#8212;&gt;+&lt;]&gt;+++.&#8212;&#8212;.+[&#8212;-&gt;+&lt;]&gt;+++.-[&#8212;&gt;++&lt;]&gt;&#8211;.+++++++.++++++.&#8211;.++++[-&gt;+++&lt;]&gt;.[&#8212;&gt;+&lt;]&gt;&#8212;-.+[&#8212;-&gt;+&lt;]&gt;+++.[&#8211;&gt;+++&lt;]&gt;+.&#8212;&#8211;.&#8212;&#8212;&#8212;&#8212;.&#8212;[-&gt;++++&lt;]&gt;.&#8212;&#8212;&#8212;&#8212;.&#8212;.+++++++++.-[-&gt;+++++&lt;]&gt;-.++[&#8211;&gt;+++&lt;]&gt;.&#8212;&#8212;-.&#8212;&#8212;&#8212;&#8212;.&#8212;[-&gt;++++&lt;]&gt;.&#8212;&#8212;&#8212;&#8212;.&#8212;.+++++++++.-[-&gt;+++++&lt;]&gt;-.&#8212;&#8211;[-&gt;++&lt;]&gt;-.&#8211;[&#8212;&gt;++&lt;]&gt;-. It seems my trauma comes true, &#8230; <a title=\"Finally Brainfuck, a THM writeup of BlobBlog\" class=\"read-more\" href=\"https:\/\/unordnung.net\/misc\/2020\/09\/finally-brainfuck-a-thm-writeup-of-blobblog\/\">Read more<span class=\"screen-reader-text\">Finally Brainfuck, a THM writeup of BlobBlog<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,5,4],"tags":[29,74,80],"class_list":["post-509","post","type-post","status-publish","format-standard","hentry","category-blah","category-ctf-writeup","category-to_remember","tag-hacking","tag-tryhackme","tag-writeup"],"_links":{"self":[{"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/posts\/509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/comments?post=509"}],"version-history":[{"count":0,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/posts\/509\/revisions"}],"wp:attachment":[{"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/media?parent=509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/categories?post=509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unordnung.net\/misc\/wp-json\/wp\/v2\/tags?post=509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}