{"id":317,"date":"2019-01-17T06:12:58","date_gmt":"2019-01-17T06:12:58","guid":{"rendered":"https:\/\/mrjsec.co.uk\/blog\/?p=317"},"modified":"2019-01-17T06:13:04","modified_gmt":"2019-01-17T06:13:04","slug":"objective-7-hr-incident-response","status":"publish","type":"post","link":"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/","title":{"rendered":"<center>Objective 7: HR Incident Response<\/center>"},"content":{"rendered":"\n<p style=\"text-align:center\">&#8220;Santa uses an Elf Resources website to look for talented information security professionals. Gain access to the website and fetch the document C:\\candidate_evaluation.docx. Which terrorist organisation is secretly supported by the job applicant whose name begins with &#8220;K.&#8221; For hints on achieving this objective, please visit Sparkle Redberry and help her with the Dev Ops Fail Cranberry Pi terminal challenge.&#8221;<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"549\" height=\"293\" data-attachment-id=\"318\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse1\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse1.png?fit=549%2C293&amp;ssl=1\" data-orig-size=\"549,293\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse1\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse1.png?fit=549%2C293&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse1.png?resize=549%2C293&#038;ssl=1\" alt=\"\" class=\"wp-image-318\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse1.png?w=549&amp;ssl=1 549w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse1.png?resize=300%2C160&amp;ssl=1 300w\" sizes=\"auto, (max-width: 549px) 100vw, 549px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">In this one we need to grab a file called candidate_evaluation.docx, sounds pretty simple. However, is it?<\/p>\n\n\n\n<p style=\"text-align:center\">If we have completed the Dev Ops Fail Cranberry Pi terminal challenge by Sparkle Redberry, and speak to them again, we get a hint which is.<br>\n&#8220;Oh my golly gracious &#8211; Tangle was right? Was it still in there? How embarrassing!<br>\nWell, if I can try to redeem myself a bit, let me tell you about another challenge you can help us.<br>\nI wonder if Tangle Coalbox has taken a good look at his employee&#8217;s import system.<br>\nIt takes CSV files as imports. That certainly can expedite a process, but there&#8217;s a danger to be had.<br>\nI&#8217;ll bet, with the right malicious input, some naughty actor could exploit a vulnerability there.<br>\nI&#8217;m sure the danger can be mitigated. OWASP has guidance on what not to allow with such uploads.&#8221;<\/p>\n\n\n\n<p style=\"text-align:center\">Also, a hint <a href=\"https:\/\/www.owasp.org\/index.php\/CSV_Injection\">link.<\/a><\/p>\n\n\n\n<p style=\"text-align:center\">Going to https:\/\/careers.kringlecastle.com\/ were asked to enter some information and upload a CSV of our past work history, <br>\nI left all the information blank and uploaded a CSV with only the words &#8220;test&#8221; in it.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"543\" height=\"788\" data-attachment-id=\"319\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse2\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse2.png?fit=543%2C788&amp;ssl=1\" data-orig-size=\"543,788\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse2\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse2.png?fit=543%2C788&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse2.png?resize=543%2C788&#038;ssl=1\" alt=\"\" class=\"wp-image-319\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse2.png?w=543&amp;ssl=1 543w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse2.png?resize=207%2C300&amp;ssl=1 207w\" sizes=\"auto, (max-width: 543px) 100vw, 543px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Also, we get a thank you message, and once again it hints where the file is &#8220;what a little tease&#8221;.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"434\" height=\"374\" data-attachment-id=\"321\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse3\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse3.png?fit=434%2C374&amp;ssl=1\" data-orig-size=\"434,374\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse3\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse3.png?fit=434%2C374&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse3.png?resize=434%2C374&#038;ssl=1\" alt=\"\" class=\"wp-image-321\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse3.png?w=434&amp;ssl=1 434w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse3.png?resize=300%2C259&amp;ssl=1 300w\" sizes=\"auto, (max-width: 434px) 100vw, 434px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">I wonder what happens if we try and find the file using the URL https:\/\/careers.kringlecastle.com\/Book1.csv and we get a 404 not found page\u2026 Again it teases us about where the data is!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"714\" height=\"563\" data-attachment-id=\"322\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse4\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse4.png?fit=714%2C563&amp;ssl=1\" data-orig-size=\"714,563\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse4\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse4.png?fit=700%2C552&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse4.png?fit=700%2C552&amp;ssl=1\" alt=\"\" class=\"wp-image-322\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse4.png?w=714&amp;ssl=1 714w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse4.png?resize=300%2C237&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse4.png?resize=700%2C552&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">We&#8217;ll let&#8217;s boot up Burp and see what we can play with here, I upload the file again, and this is what I see in Burp.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"814\" height=\"536\" data-attachment-id=\"323\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse5\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse5.png?fit=814%2C536&amp;ssl=1\" data-orig-size=\"814,536\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse5\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse5.png?fit=700%2C461&amp;ssl=1\" src=\"https:\/\/i2.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse5.png?fit=700%2C461&amp;ssl=1\" alt=\"\" class=\"wp-image-323\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse5.png?w=814&amp;ssl=1 814w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse5.png?resize=300%2C198&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse5.png?resize=768%2C506&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse5.png?resize=700%2C461&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Interesting, I can see the text &#8220;test&#8221; which is the only text I have within my CSV, so let&#8217;s look into CSV Injection. (You can find links, as well as a Video from Kringlecon)<\/p>\n\n\n\n<p style=\"text-align:center\">At first, I was thinking of doing it with a shell and downloading the file\u2026 However, then I would need to open ports and do other such stuff, So its more comfortable to <a href=\"http:\/\/ https:\/\/docs.microsoft.com\/en-us\/windows-server\/administration\/windows-commands\/copy\">copy<\/a> the file.<br><\/p>\n\n\n\n<p style=\"text-align:center\">We know where the public folder is, as the 404 shows it! <br>\nSo let&#8217;s create the corrupt CSV file! (In this case, I use the same file, CSV with the word &#8220;test&#8221; in it, edit this in the burp.<br>\nLike so<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"639\" data-attachment-id=\"324\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse6\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse6.png?fit=770%2C639&amp;ssl=1\" data-orig-size=\"770,639\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse6\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse6.png?fit=700%2C581&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse6.png?fit=700%2C581&amp;ssl=1\" alt=\"\" class=\"wp-image-324\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse6.png?w=770&amp;ssl=1 770w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse6.png?resize=300%2C249&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse6.png?resize=768%2C637&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse6.png?resize=700%2C581&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<pre class=\"wp-block-code\"><code>=cmd|' \/C copy C:\\candidate_evaluation.docx C:\\careerportal\\resources\\public\\swaglife.docx'!A1<\/code><\/pre>\n\n\n\n<p style=\"text-align:center\">Also, there was much chat going on about PowerShell not working; I can confirm PowerShell is working and enabled, so you could also use this command.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>=cmd|' \/C powershell copy C:\\candidate_evaluation.docx C:\\careerportal\\resources\\public\\swaglife.docx'!A1<\/code><\/pre>\n\n\n\n<p style=\"text-align:center\">(Both work!)<\/p>\n\n\n\n<p style=\"text-align:center\">Run the command and let&#8217;s go the URL, https:\/\/careers.kringlecastle.com\/public\/swaglife.docx<br>so here is our<a href=\"https:\/\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/swaglife.pdf\"> file<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"1187\" height=\"523\" data-attachment-id=\"325\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse7\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse7.png?fit=1187%2C523&amp;ssl=1\" data-orig-size=\"1187,523\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse7\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse7.png?fit=700%2C308&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse7.png?fit=700%2C308&amp;ssl=1\" alt=\"\" class=\"wp-image-325\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse7.png?w=1187&amp;ssl=1 1187w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse7.png?resize=300%2C132&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse7.png?resize=768%2C338&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse7.png?resize=700%2C308&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Now we need to find which terrorist organisation secretly supported by the job applicant whose name begins with &#8220;K.&#8221;\u2026 So it looks like that is Krampus, so the answer is Fancy Beaver!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"746\" height=\"797\" data-attachment-id=\"329\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse8\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse8.png?fit=746%2C797&amp;ssl=1\" data-orig-size=\"746,797\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse8\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse8.png?fit=700%2C748&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse8.png?fit=700%2C748&amp;ssl=1\" alt=\"\" class=\"wp-image-329\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse8.png?w=746&amp;ssl=1 746w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse8.png?resize=281%2C300&amp;ssl=1 281w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse8.png?resize=700%2C748&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"757\" height=\"484\" data-attachment-id=\"330\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/objective-7-hr-incident-response\/hrincidentresponse9\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse9.png?fit=757%2C484&amp;ssl=1\" data-orig-size=\"757,484\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"HRIncidentResponse9\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse9.png?fit=700%2C448&amp;ssl=1\" src=\"https:\/\/i1.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse9.png?fit=700%2C448&amp;ssl=1\" alt=\"\" class=\"wp-image-330\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse9.png?w=757&amp;ssl=1 757w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse9.png?resize=300%2C192&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2019\/01\/HRIncidentResponse9.png?resize=700%2C448&amp;ssl=1 700w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p style=\"text-align:center\">Moreover, that&#8217;s it, another challenge down.<\/p>\n\n\n\n<p style=\"text-align:center\">References:<br>\nhttps:\/\/www.exploit-db.com\/exploits\/45234<br>\nhttp:\/\/www.tothenew.com\/blog\/csv-injection\/<br>\nhttps:\/\/www.owasp.org\/index.php\/CSV_Injection<br>\nhttps:\/\/payatu.com\/csv-injection-basic-to-exploit\/<br>\nhttps:\/\/blog.zsec.uk\/csv-dangers-mitigations\/<br>\nhttps:\/\/github.com\/swisskyrepo\/PayloadsAllTheThings\/tree\/master\/CSV%20injection<br>\nhttps:\/\/www.youtube.com\/watch?v=Z3qpcKVv2Bg<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;Santa uses an Elf Resources website to look for talented information security professionals. Gain access to the website and fetch the document C:\\candidate_evaluation.docx. Which terrorist organisation is secretly supported by the job applicant whose name&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[10],"tags":[13,14,12],"class_list":["post-317","post","type-post","status-publish","format-standard","hentry","category-kringlecon-2018","tag-13","tag-ctf","tag-kringlecon"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paD3U6-57","_links":{"self":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=317"}],"version-history":[{"count":4,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/317\/revisions"}],"predecessor-version":[{"id":331,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/317\/revisions\/331"}],"wp:attachment":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}