{"id":250,"date":"2019-01-17T05:23:58","date_gmt":"2019-01-17T05:23:58","guid":{"rendered":"https:\/\/mrjsec.co.uk\/blog\/?p=250"},"modified":"2019-01-17T05:24:06","modified_gmt":"2019-01-17T05:24:06","slug":"objective-3-de-bruijn-sequences","status":"publish","type":"post","link":"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/","title":{"rendered":"<center>Objective 3: De Bruijn Sequences<\/center>"},"content":{"rendered":"\n<p style=\"text-align:center\">In objective 3, we need to gain access to the into the speaker unpreparedness room, however, the door locked with some fancy code.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"530\" height=\"232\" data-attachment-id=\"251\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture1-6\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-5.png?fit=530%2C232&amp;ssl=1\" data-orig-size=\"530,232\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture1\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-5.png?fit=530%2C232&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-5.png?resize=530%2C232&#038;ssl=1\" alt=\"\" class=\"wp-image-251\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-5.png?w=530&amp;ssl=1 530w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture1-5.png?resize=300%2C131&amp;ssl=1 300w\" sizes=\"auto, (max-width: 530px) 100vw, 530px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"430\" height=\"452\" data-attachment-id=\"252\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture2-6\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-5.png?fit=430%2C452&amp;ssl=1\" data-orig-size=\"430,452\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture2\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-5.png?fit=430%2C452&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-5.png?resize=430%2C452&#038;ssl=1\" alt=\"\" class=\"wp-image-252\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-5.png?w=430&amp;ssl=1 430w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture2-5.png?resize=285%2C300&amp;ssl=1 285w\" sizes=\"auto, (max-width: 430px) 100vw, 430px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">If we have compleated Lethal ForensicELFication Cranberry Pi terminal challenge by Tangle Coalbox, then we can get a hint which is.<br> &#8220;Hey, thanks for the help with the investigation, gumshoe.<br> Have you been able to solve the lock with the funny shapes?<br> It reminds me of something called &#8220;de Bruijn Sequences.&#8221;<br> You can optimise the guesses because there is no start and stop &#8212; each new value added to the end, and the first removed.<br> I&#8217;ve even seen de Bruijn sequence generators online.<br> Here the length of the alphabet is 4 (only four buttons), and the length of the PIN is four as well.<br> Mathematically this is k=4, n=4 to generate the de Bruijn sequence.<br> Math is like your notepad and pencil &#8211; can&#8217;t leave home without it!<br> I heard Alabaster lost his badge! That&#8217;s pretty bad. What do you think someone could do with that?&#8221;<br> Also, a <a href=\"http:\/\/www.hakank.org\/comb\/debruijn.cgi\">link<\/a> too.<\/p>\n\n\n\n<p style=\"text-align:center\">When we try to access the door were greeted with this screen, &#8220;Enter the code top unlock door&#8221; and four shapes triangle, square, circle and a star.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"619\" height=\"355\" data-attachment-id=\"254\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture3-6\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-5.png?fit=619%2C355&amp;ssl=1\" data-orig-size=\"619,355\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture3\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-5.png?fit=619%2C355&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-5.png?resize=619%2C355&#038;ssl=1\" alt=\"\" class=\"wp-image-254\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-5.png?w=619&amp;ssl=1 619w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture3-5.png?resize=300%2C172&amp;ssl=1 300w\" sizes=\"auto, (max-width: 619px) 100vw, 619px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Now there are two methods to unlocking the door here; one is doing the whole &#8220;Math is like your notepad and pencil &#8211; can&#8217;t leave home without it!&#8221; and reading the hint carefully!<\/p>\n\n\n\n<p style=\"text-align:center\">Like here &#8220;You can optimise the guesses because there is no start and stop &#8212; each new value added to the end, and the first removed.&#8221;\u2026 &#8220;each new value is added to the end, and the first removed.&#8221; &#8220;Here the length of the alphabet is 4 (only four buttons), and the length of the PIN is four as well.&#8221;<\/p>\n\n\n\n<p style=\"text-align:center\">Ok, So let&#8217;s look at the HTML code here, we can see there are four shapes on the screen. However, in the system, it reads as 0=triangle, 1=square, 2=circle and 3=star.<br>\nI used Firefox inspector mode here.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1278\" height=\"919\" data-attachment-id=\"255\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture4-6\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-5.png?fit=1278%2C919&amp;ssl=1\" data-orig-size=\"1278,919\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture4\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-5.png?fit=700%2C503&amp;ssl=1\" src=\"https:\/\/i2.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-5.png?fit=700%2C503&amp;ssl=1\" alt=\"\" class=\"wp-image-255\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-5.png?w=1278&amp;ssl=1 1278w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-5.png?resize=300%2C216&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-5.png?resize=768%2C552&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture4-5.png?resize=700%2C503&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Now, going back to the hint &#8220;each new value is added to the end, and the first removed.&#8221; and &#8220;Here the length of the alphabet is 4 (only four buttons)&#8221; I&#8217;m not the best at explaining Sequences so warning here!<br>\nThe length of the code is 4, and new values added to the end, and the first one removed. So, simply the code is 0,1,2,0 (triangle,square,circle,triangle). Why? So, there are four buttons 1,2,3,4. However, the code shows it as 0,1,2,3 (So we only have 3, if you start from 0).<br>\nIf the code is four length, and we only have three numbers (counting from 0), then we need to loop from 2 and remove 3, making the code 0,1,2,(remove 3, and jump back from the start)0. &lt;- So triangle(&#8220;0&#8221;) becomes 0 and 4!\u2026.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"609\" height=\"445\" data-attachment-id=\"256\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture5-5\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-4.png?fit=609%2C445&amp;ssl=1\" data-orig-size=\"609,445\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture5\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-4.png?fit=609%2C445&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-4.png?resize=609%2C445&#038;ssl=1\" alt=\"\" class=\"wp-image-256\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-4.png?w=609&amp;ssl=1 609w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture5-4.png?resize=300%2C219&amp;ssl=1 300w\" sizes=\"auto, (max-width: 609px) 100vw, 609px\" \/><\/figure>\n\n\n\n<p style=\"text-align:center\">Yeh, I agree it&#8217;s not the best example I do apologise for this. Singingbanana on YouTbube examples it better <a href=\"https:\/\/www.youtube.com\/watch?v=iPLQgXUiU14\">here <\/a>. You can also check out the <a href=\"https:\/\/en.wikipedia.org\/wiki\/De_Bruijn_sequence\">Wiki<\/a> and don&#8217;t forget the hint <a href=\"http:\/\/www.hakank.org\/comb\/debruijn.cgi\">link<\/a>  even this <a href=\"https:\/\/jgeisler0303.github.io\/deBruijnDecode\/#decoderTest\">link.<\/a><\/p>\n\n\n\n<p style=\"text-align:center\">\u2026\u2026\u2026\u2026\u2026 Alternatively, I guess you could brute force it! <\/p>\n\n\n\n<p style=\"text-align:center\">Using Firefox inspector mode again, we can find the URL of the challenge page here https:\/\/doorpasscode.kringlecastle.com\/?challenge=doorpasscode&amp;id=74547565-107d-40e1-97ef-5a2e3a594b94.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1294\" height=\"864\" data-attachment-id=\"257\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture6-4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-3.png?fit=1294%2C864&amp;ssl=1\" data-orig-size=\"1294,864\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture6\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-3.png?fit=700%2C467&amp;ssl=1\" src=\"https:\/\/i2.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-3.png?fit=700%2C467&amp;ssl=1\" alt=\"\" class=\"wp-image-257\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-3.png?w=1294&amp;ssl=1 1294w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-3.png?resize=300%2C200&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-3.png?resize=768%2C513&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture6-3.png?resize=700%2C467&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1042\" height=\"406\" data-attachment-id=\"258\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture7-4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-3.png?fit=1042%2C406&amp;ssl=1\" data-orig-size=\"1042,406\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture7\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-3.png?fit=700%2C273&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-3.png?fit=700%2C273&amp;ssl=1\" alt=\"\" class=\"wp-image-258\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-3.png?w=1042&amp;ssl=1 1042w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-3.png?resize=300%2C117&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-3.png?resize=768%2C299&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture7-3.png?resize=700%2C273&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Perfect this makes it easier for us and to use Burp Suite (You could use other programs, or even create a python script, but I use Burp Suite as it&#8217;s well known).<br>\nIn Burp Suite, we want to capture the request sent.<\/p>\n\n\n\n<p style=\"text-align:center\">(In this cause I just sent an incorrect guess to get a replay).<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"192\" data-attachment-id=\"259\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture8-4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-3.png?fit=851%2C233&amp;ssl=1\" data-orig-size=\"851,233\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture8\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-3.png?fit=700%2C192&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-3.png?resize=700%2C192&#038;ssl=1\" alt=\"\" class=\"wp-image-259\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-3.png?resize=700%2C192&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-3.png?resize=300%2C82&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-3.png?resize=768%2C210&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture8-3.png?w=851&amp;ssl=1 851w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">In Burp Suite we can see the request sent, and we can see the shape numbers (3,3,3,2, star, star, star, circle).<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"851\" height=\"233\" data-attachment-id=\"260\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture9\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9.png?fit=851%2C233&amp;ssl=1\" data-orig-size=\"851,233\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture9\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9.png?fit=700%2C192&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9.png?fit=700%2C192&amp;ssl=1\" alt=\"\" class=\"wp-image-260\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9.png?w=851&amp;ssl=1 851w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9.png?resize=300%2C82&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9.png?resize=768%2C210&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture9.png?resize=700%2C192&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">So in the Response, we can see the message &#8220;{&#8220;success&#8221;:false,&#8221;message&#8221;:&#8221;Incorrect guess.&#8221;}&#8221;, great! Now we know if we got it or not during the brute force attack.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"594\" height=\"248\" data-attachment-id=\"261\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture10\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10.png?fit=594%2C248&amp;ssl=1\" data-orig-size=\"594,248\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture10\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10.png?fit=594%2C248&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10.png?resize=594%2C248&#038;ssl=1\" alt=\"\" class=\"wp-image-261\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10.png?w=594&amp;ssl=1 594w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture10.png?resize=300%2C125&amp;ssl=1 300w\" sizes=\"auto, (max-width: 594px) 100vw, 594px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Let&#8217;s send this request to the Intruder and select where the door code goes &#8220;this is we tell Burp Suite to try different inputs.&#8221;<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1195\" height=\"366\" data-attachment-id=\"262\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture11\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11.png?fit=1195%2C366&amp;ssl=1\" data-orig-size=\"1195,366\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture11\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11.png?fit=700%2C214&amp;ssl=1\" src=\"https:\/\/i2.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11.png?fit=700%2C214&amp;ssl=1\" alt=\"\" class=\"wp-image-262\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11.png?w=1195&amp;ssl=1 1195w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11.png?resize=300%2C92&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11.png?resize=768%2C235&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture11.png?resize=700%2C214&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Once you have this set, let&#8217;s head over to &#8220;Payloads&#8221; within the Intruder tab and set &#8220;Payload type to Brute forcer&#8221; and &#8220;Character set to 0123&#8221; (again it goes 0,1,2,3 and not 1,2,3,4) and &#8220;Min length to 4 and Max length to 4.&#8221;<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1198\" height=\"369\" data-attachment-id=\"263\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture12\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12.png?fit=1198%2C369&amp;ssl=1\" data-orig-size=\"1198,369\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture12\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12.png?fit=700%2C216&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12.png?fit=700%2C216&amp;ssl=1\" alt=\"\" class=\"wp-image-263\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12.png?w=1198&amp;ssl=1 1198w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12.png?resize=300%2C92&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12.png?resize=768%2C237&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture12.png?resize=700%2C216&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Once ready just hit the &#8220;Start attack&#8221; button and sit back and wait\u2026\u2026 Also, wait. So wait a bit more. Burp Suite has calculated (from what we have entered) that there are 256 combinations here, and Burp Suite use them all!<\/p>\n\n\n\n<p style=\"text-align:center\">After some time, Burp Sutie will be complated and will have tried all 256 combinations! Going down the list, we can see one requst has a length of &#8220;353&#8221; and the others only have a length of &#8220;229&#8221;<br> That&#8217;s because the response given back is different and this time it says.<\/p>\n\n\n\n<p style=\"text-align:center\">&#8220;{&#8220;success&#8221;:true,&#8221;resourceId&#8221;:&#8221;af6e7a79-8328-429d-8ebd-bb6c7e849c39&#8243;,&#8221;hash&#8221;:&#8221;47d4f4739a6dc39076d22a6e6a926164dabafed3f190fdc5dce3bf980bf35acf&#8221;,&#8221;message&#8221;:&#8221;Correct guess!&#8221;}&#8221;<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1292\" height=\"575\" data-attachment-id=\"264\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture13\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13.png?fit=1292%2C575&amp;ssl=1\" data-orig-size=\"1292,575\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture13\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13.png?fit=700%2C312&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13.png?fit=700%2C312&amp;ssl=1\" alt=\"\" class=\"wp-image-264\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13.png?w=1292&amp;ssl=1 1292w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13.png?resize=300%2C134&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13.png?resize=768%2C342&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture13.png?resize=700%2C312&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">So that&#8217;s it, you have successfully brute forced the correct combination and can now enter the speaker unpreparedness room and get the answer for objective three which is &#8220;Welcome unprepared speaker!&#8221;<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"338\" height=\"465\" data-attachment-id=\"265\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture14\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14.png?fit=338%2C465&amp;ssl=1\" data-orig-size=\"338,465\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture14\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14.png?fit=338%2C465&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14.png?resize=338%2C465&#038;ssl=1\" alt=\"\" class=\"wp-image-265\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14.png?w=338&amp;ssl=1 338w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture14.png?resize=218%2C300&amp;ssl=1 218w\" sizes=\"auto, (max-width: 338px) 100vw, 338px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"516\" height=\"176\" data-attachment-id=\"266\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-3-de-bruijn-sequences\/capture15\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15.png?fit=516%2C176&amp;ssl=1\" data-orig-size=\"516,176\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Capture15\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15.png?fit=516%2C176&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15.png?resize=516%2C176&#038;ssl=1\" alt=\"\" class=\"wp-image-266\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15.png?w=516&amp;ssl=1 516w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/Capture15.png?resize=300%2C102&amp;ssl=1 300w\" sizes=\"auto, (max-width: 516px) 100vw, 516px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">References:<br>\nhttps:\/\/hackaday.com\/2018\/06\/18\/opening-a-ford-with-a-robot-and-the-de-bruijn-sequence\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In objective 3, we need to gain access to the into the speaker unpreparedness room, however, the door locked with some fancy code. If we have compleated Lethal ForensicELFication Cranberry Pi terminal challenge by Tangle&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[10],"tags":[13,14,12],"class_list":["post-250","post","type-post","status-publish","format-standard","hentry","category-kringlecon-2018","tag-13","tag-ctf","tag-kringlecon"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paD3U6-42","_links":{"self":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/250","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=250"}],"version-history":[{"count":2,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/250\/revisions"}],"predecessor-version":[{"id":268,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/250\/revisions\/268"}],"wp:attachment":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}