Sans Hack Challenge 2016 – the 7th audio

Right, so let’s continue last post and look at getting the final audio file.

Running nmap -sC analytics.northpolewonderland.com gets me something very interesting, namely a .git directory, that’s accessible over http:


443/tcp open https
| http-git:
| 104.198.252.157:443/.git/
| Git repository found!

I can get its contents like this:
wget --no-check-certificate --mirror -I .git https://104.198.252.157/.git/
At this point I only have the git history, but no files. No problem, I can get the files as follows:
git checkout -- . restores all files from git history

Continue reading