[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/labyrenth-capture-the-flag-ctf-unix-track-solutions/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/labyrenth-capture-the-flag-ctf-unix-track-solutions/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/ "Learning Hub")
* [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/ "Cybersecurity Tutorials")  
  [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)

# LabyREnth Capture the Flag (CTF): Unix Track Solutions

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 12 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Richard Wartell](https://unit42.paloaltonetworks.com/author/richard-wartell/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 25, 2016

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)
  * [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CTF](https://unit42.paloaltonetworks.com/tag/ctf/)
  * [LabyREnth](https://unit42.paloaltonetworks.com/tag/labyrenth/)
  * [Unix](https://unit42.paloaltonetworks.com/tag/unix/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/labyrenth-capture-the-flag-ctf-unix-track-solutions/?pdf=download&lg=en&_wpnonce=ac4b3be3b8 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/labyrenth-capture-the-flag-ctf-unix-track-solutions/?pdf=print&lg=en&_wpnonce=ac4b3be3b8 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=LabyREnth%20Capture%20the%20Flag%20(CTF):%20Unix%20Track%20Solutions&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Flabyrenth-capture-the-flag-ctf-unix-track-solutions%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Flabyrenth-capture-the-flag-ctf-unix-track-solutions%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flabyrenth-capture-the-flag-ctf-unix-track-solutions%2F&title=LabyREnth%20Capture%20the%20Flag%20(CTF):%20Unix%20Track%20Solutions> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flabyrenth-capture-the-flag-ctf-unix-track-solutions%2F&text=LabyREnth%20Capture%20the%20Flag%20(CTF):%20Unix%20Track%20Solutions> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flabyrenth-capture-the-flag-ctf-unix-track-solutions%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=LabyREnth%20Capture%20the%20Flag%20(CTF):%20Unix%20Track%20Solutions%20https%3A%2F%2Funit42.paloaltonetworks.com%2Flabyrenth-capture-the-flag-ctf-unix-track-solutions%2F> "Share in Mastodon")
  Thanks to the incredibly talented community of threat researchers that participated in [LabyREnth, the Unit 42 Capture the Flag (CTF)](https://blog.paloaltonetworks.com/2016/07/unit42-announcing-the-labyrenth-capture-the-flag-ctf-challenge/) challenge. Now that the challenge is closed, we can finally reveal the solutions of each challenge track. We'll be rolling out the [solutions](https://blog.paloaltonetworks.com/tag/ctf/) for one challenge track per week. Next up, the Unix track.

### Unix 1 Challenge: Layers upon layers of \_\_\_\_\_s of wisdom.

*Challenge Created By: Richard Wartell [@wartortell](https://twitter.com/wartortell)*

We are given a perl script that when executed tells us we are doing a thing and then says stahp.

$perl bowie.pl  
You're doing a thing...  
AAAA  
stahp

If we look at the script source, we can see that it has a series of nested if else conditions. At each layer, the script requests user input which it uses for the next if condition. If the if conditions are true, an additional base64 chunk is decoded and appended to the $a variable.

print "You're doing a thing...\\n";  
my $input = \<STDIN\>;  
$input = trim($input);  
if ($input eq (chr(5156 - 5035) . chr(-4615 - -4716) . chr(3162 - 3047))) {  
$a = $a . MIME::Base64::decode("...")

This repeats many times until the last if condition which evals a base64 block.

eval MIME::Base64::decode("...")

We can use python to base64 decode each of these blocks ourselves. When we decode the eval block it has a block that is decoded and appended to the '$a' variable and another block that is eval'd. This repeats over and over many times. If we grab each block that appends to the '$a' variable, decode them, and write them to a file, we find that it is a jpg and contains the key.

from base64 import b64de

a = b64decode("R0lGODlh2  
a = a + b64decode("KmZRg  
...  
a = a + b64decode("7w3jz  
f = open("out.gif", "w")  
f.write(a)

When I was working the challenge, I manually kept decoding each block and writing it until I got enough of the picture for the key.

[![CTF2\_1](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_1-1-230x282.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_1-1.png)  
Jeff White solved the entire solution with a bash one liner that is a thing of beauty.

cp bowie.pl bowie\_1 \&\& for i in $(seq 1 50); do grep -E "\\$a|eval" bowie\_$i |cut -d"\\"" -f2 |base64 -D \> bowie\_`expr $i + 1` ; done \&\& for i in $(grep "\\$a" bowie\_1 |cut -d"\\"" -f2); do echo $i |base64 -D \>\> bowie.gif; done \&\& for i in $(find . -size +2k -ls |cut -d"/" -f2 |grep -vE "bowie\_1$|bowie.pl" |sort -t \_ -k 2 -n); do grep "\\$a" $i |cut -d"\\"" -f2 |base64 -D \>\> bowie.gif; done \&\& rm bowie\_\* \&\& open bowie.gif \&\& echo "D4rkCryst4lz"

### Unix 2 Challenge: Melted cowboys and space wrestling; this isn't the Ninth Wonder of the World. Maybe because we're all a little rusty.

*Challenge Created By: Anthony Kasza [@anthonykasza](https://twitter.com/anthonykasza)*

We are given a 64bit ELF challenge binary.

$file challenge  
challenge: ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.32, BuildID\[sha1\]=4570af615de39c4912c17a09f9fbf8419368572b, not stripped

We start off by running it and see a message that says, "Let's party like it's 1999!" and then the html contents of example.com.  
./challenge Let's party like it's 1999!! \<!doctype html\> \<html\> \<head\> \<title\>Example Domain\</title\> \<meta charset="utf-8" /\> \<meta http-equiv="Content-type" content="text/html; charset=utf-8" /\> \<meta name="viewport" content="width=device-width, initial-scale=1" /\> \<style type="text/css"\> body { background-color: #f0f0f2; margin: 0; padding: 0; font-family: "Open Sans", "Helvetica Neue", Helvetica, Arial, sans-serif; } div { width: 600px; margin: 5em auto; padding: 50px; background-color: #fff; border-radius: 1em; } a:link, a:visited { color: #38488f; text-decoration: none; } @media (max-width: 700px) { body { background-color: #fff; } div { width: auto; margin: 0 auto; border-radius: 0; padding: 1em; } } \</style\> \</head\> \<body\> \<div\> \<h1\>Example Domain\</h1\> \<p\>This domain is established to be used for illustrative examples in documents. You may use this domain in examples without prior coordination or asking for permission.\</p\> \<p\>\<a href="http://www.iana.org/domains/example"\>More information...\</a\>\</p\> \</div\> \</body\> \</html\>

|----------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 | ./challenge Let's party like it's 1999!! \<!doctype html\> \<html\> \<head\> \<title\>Example Domain\</title\> \<meta charset="utf-8" /\> \<meta http-equiv="Content-type" content="text/html; charset=utf-8" /\> \<meta name="viewport" content="width=device-width, initial-scale=1" /\> \<style type="text/css"\> body { background-color: #f0f0f2; margin: 0; padding: 0; font-family: "Open Sans", "Helvetica Neue", Helvetica, Arial, sans-serif; } div { width: 600px; margin: 5em auto; padding: 50px; background-color: #fff; border-radius: 1em; } a:link, a:visited { color: #38488f; text-decoration: none; } @media (max-width: 700px) { body { background-color: #fff; } div { width: auto; margin: 0 auto; border-radius: 0; padding: 1em; } } \</style\> \</head\> \<body\> \<div\> \<h1\>Example Domain\</h1\> \<p\>This domain is established to be used for illustrative examples in documents. You may use this domain in examples without prior coordination or asking for permission.\</p\> \<p\>\<a href="http://www.iana.org/domains/example"\>More information...\</a\>\</p\> \</div\> \</body\> \</html\> |

I perform stings on the binary and see some interesting ones related to dates, example.com, and rust.

...  
http://www.example.com  
stream did not contain valid UTF-8  
1/1/1999%d/%m/%Y  
This system is obviously not a 90's kid.1/1/2000Possible Y2K issue.  
What year is it?!  
%a, %d %b %Y %H:%M:%S GMT  
That Date isn't RFC compliant  
That response was not OK  
Let's party like it's 1999!!  
...  
rust\_builtin.c  
rust\_begin\_unwind  
rust\_eh\_personality  
rust\_eh\_personality\_catch  
...

Next we open it up and look at it in IDA and after demangling the names, we can see a pretty large main function. We can start by using IDA's cross references on some of those interesting date strings we found earlier. We see that an http request is made to [www.example.com](https://www.example.com) and the headers are checked for the date. This gives us a pretty good idea of what we can try to fiddle with.

[![CTF2\_2](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_2-230x459.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_2.png)

I setup an Ubuntu virtual machine on a private virtual network and then created another linked clone to have a server. I changed the hosts file on the client system to point [www.example.com](https://www.example.com) to the other server system. I also installed nginx on the server system to have an easy http listener.

[![CTF2\_3](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_3-230x58.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_3.png)

I tried to run the program with the current date and it printed out the nginx response and then I changed the date back to 1999 like the challenge asks and it printed out the key.

PAN{ThaddeusVenture}

[![CTF2\_4](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_4-230x208.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_4.png)

### Unix 3 Challenge: Far above the world sitting in your tin can the stars look very different today

*Challenge Created By: Tyler Halfpop [@0xtyh](https://twitter.com/0xtyh)*

We are given an ELF file and when it runs, it draws a nice cat.

$./odd8\_v1 [![Screen Shot 2016-08-25 at 2.58.05 PM copy](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Screen-Shot-2016-08-25-at-2.58.05-PM-copy-230x198.jpg)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Screen-Shot-2016-08-25-at-2.58.05-PM-copy.jpg)

When we open it in IDA and go to graph mode in the main function, we can see the key drawn by the nodes.

[![CTF2\_5](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_5-230x129.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_5.png)

The binary was constructed using the [REpsych](https://github.com/xoreaxeaxeax/REpsych) framework by [@xoreaxeaxeax](https://twitter.com/xoreaxeaxeax).

### Unix 4 Challenge: Sometimes you find treasure in the oddest of places...

*Challenge Created By: karttoon [@noottrak](https://twitter.com/noottrak)*

We receive this beautiful image to start with.

[![CTF2\_6](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_6-230x140.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_6.png)

I opened the image with my favorite hex editor, 010Editor, and I could see there is a large blob at the end of the image after the FF D9 ending of the jpg.

[![CTF2\_7](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_7-230x107.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_7.png)

I extracted the blob and divided the sections that were separated by tags. There was a coppertunnel, goldtunnel, silvertunnel, and a crystal tunnel. Each section looked like base64, but the padding was at the beginning with the =. I used 010Editor's built in Ascii reverse script to reverse the text and then 010Editor's decode base64 script. It looked like I had backwards base64 again, so I repeated this step several times until I got a PK zip header. I did this procedure for each tunnel getting to the file before the zip file and then I used python to write the final file.

from base64 import b64decode

ci = open("coppertunnel.txt", "rb").read()  
co = open("copperout.zip", "w")  
co.write(b64decode(ci))

si = open("silvertunnel.txt", "rb").read()  
so = open("silverout.zip", "w")  
so.write(b64decode(ci))

gi = open("goldtunnel.txt", "rb").read()  
go = open("goldout.zip", "w")  
go.write(b64decode(ci))

cri = open("crystaltunnel.txt", "rb").read()  
cro = open("crystalout.zip", "w")  
cro.write(b64decode(ci))

I unzipped the files and saw that I had 4 parts of a Par archive.

treasure.vol306+306 2.par2  
treasure.vol306+306 3.par2  
treasure.vol306+306 4.par2  
treasure.vol306+306.par2

I did some Googling and found MultiPar to work with the files. I was able to use the Repair function to restore a chest.zip file.

[![CTf2\_8](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTf2_8-230x147.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTf2_8.png)

Chest.zip was an encrypted zip file, so I started to look for the password in the original image. I tried steghide and it outputted bards\_song, which was a text file with excellent instructions that would have been helpful earlier on, and the password for the zip file.

steghide.exe extract -sf labyrinth\_entrance.jpg  
Enter passphrase:  
wrote extracted data to "bards\_song".

Over the hills and through the grass  
By dawn of light in the mountain pass  
The goblins treasure awaits the steadfast  
Walking in REVerse, the eye opens as you go past  
A smell leads you onward, luring you to follow  
At the end of each tunnel, a PARt of treasure in the hollow  
Combine them to find a door hidden by rhyme  
Opened once with the words "aintnobodygottime"

I was then able to unzip the chest.zip, which gave me a MachO called jareths\_maze. I ran it in a VM and I was greeted with this horrifying ascii art.

[![CTF2\_9](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_9-230x197.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/CTF2_9.png)

I couldn't let the clowns win, so I had to open the file in IDA. I decompiled main and there were more clowns, but the message was different.

[![10](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/10-230x106.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/10.png)

Then I saw this demoralizing string of function names and I started to get a little freaked out.

[![11](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/11-230x731.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/11.png)

The program printed the ascii art after going through these functions. I knew that the beginning message wasn't correct and the ending message wasn't correct. Each function was overwriting a character in the message and the a group of functions was being overwritten by what the b group of functions was writing.

[![12](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/12-230x189.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/12.png)

I used IDA to jump into each function and grab the ordinal of the character that the message was supposed to be with the a functions and then I used python to convert the ordinal to the character to obtain the key.

PAN{D4nKkry5t4l}

### Unix 5 Challenge: All your filez are belongz to us.

*Challenge Created By: Tyler Halfpop [@0xtyh](https://twitter.com/0xtyh)*

We are given a binary called krypto.danger, and if we run file on it, we can see that it is a 64bit Mach-O.

file krypto.danger  
krypto.danger: Mach-O 64-bit executable x86\_64

A good first step when examining a Mach-O is to check it out in [osxreverser's branch of MachOView](https://github.com/gdbinit/MachOView) to examine the various Mach-O header information and strings, much like you would with a PE file.

[![13](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/13-230x189.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/13.png)

The next step is to run the binary to get a better understanding of what it does. We should run untrusted binaries in a virtual machine, but we are too busy looking at pictures of Mr. Bigglesworth to be bothered by that. When we run it, our picture of Mr. Bigglesworth gets encrypted and a .laby extension is appended. A menacing narwhal also pops up that ironically tells us "Congratulations! All your pngs are belong to us Pay us all the moneyz -- PANW GSRT". Not Mr. Bigglesworth! This is war.

[![Picture14](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture14-230x129.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/Picture14.png)

When we open the binary in IDA we can see all the ugly mangled Swift names.

[![15](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/15-230x225.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/15.png)

We can use an IDA Script called [SwiftDemang](https://github.com/0xtyh/SwiftDemang) to demangle the Swift names to make it easier to read. After running the script, it is a little easier to look at the function names.

[![16](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/16-230x292.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/16.png)

After demangling the functions, we can see some interesting functions like krypto\_dkrypt and krypto\_ekrypt. Krypto\_dkrypt gets called if there is a dekrypt argument. Let's try to use that to see if we can get Mr. Bigglesworth back.

[![17](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/17-230x172.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/17.png)

Now that we have Mr. Bigglesworth with us again, we can get back to solving the challenge. The dkrypt and ekrypt functions both call an interesting looking function called get\_pw that returns a string we can tell from the comment added by SwiftDemang.

[![18](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/18-230x187.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/18.png)

When we look at the get\_pw we see an interesting looking string highlighted below and calls to RNCryptor. If we Google RNCryptor, we can find an [open source Swift version of AES-256](https://github.com/RNCryptor/RNCryptor), which is being used to encrypt the password that is then used to encrypt or decrypt the files.

[![19](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/19-230x165.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/19.png)

If we setup remote debugging with IDA and break on the return from get\_pw, we can see the key to the challenge in the string pointed to by the return value in RAX at 0x100608101.

[![20](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/20-230x104.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/20.png)

### Unix 6 Challenge: Go forth good language.

*Challenge Created By: Richard Wartell ([@wartortell](https://twitter.com/wartortell))*

For this challenge, you're given a server and a client binary, both Mach.O files. If we run the client binary, we can see that it's asking for a four token key in order to get the "prize".

[![21](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/21-230x275.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/21.png)

Thankfully, these binaries haven't had their symbols stripped so it's easy to find interesting functions in the binary. From a quick look at the client library, we can see the strings that were shown above, as well as the client library sending the four tokens you enter to a server:

[![22](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/22-230x387.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/22.png)

So we need to look into how the server checks the tokens that are sent. When we open up the server in IDA Pro, we can easily see the functions main\_check\_key1, main\_check\_key2, main\_check\_key3, and main\_check\_key4 being called in a row. If we following them, there is a check which leads to where the real key would be if this was the actual server:

[![23](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/23-230x142.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/23.png)

From here, all we need to do is figure out what each token needs to be. From digging through each of the four functions, we can find the tokens that will get us the key:

1. Checks the first message character by character, the token is "3at"
2. Checks the second message, the length must be 11, and each character is pairwise compared with each one, the differences can be used to determine the characters. The token is "chInch1ll@z".
3. Performs specific checks on the token against another 4 byte string. The token is "H1gh".
4. Compares characters from the token against the string "Fromunda" and the number 183. The token is "F183r"

We know we've got the right tokens because we can run the server and client locally, and we get this:

[![24](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/24-230x111.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/24.png)

When we connect instead to the IP contained in the directions file and provide the 4 tokens, we get the key:

PAN{th@Nk5\_m4r1ha\_U\_s0\_n1c3}

### Unix 7 Challenge: Crack the codes to get the Apple

*Challenge Created By: Tyler Halfpop ([@0xtyh](https://twitter.com/0xtyh))*

This time I was handed an OSX compiled application called RedDelicious. First, I simply ran it (not smart, but I never claimed to be), and got the following window popup:

[![25](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/25-230x72.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/25.png)

So I entered some text into the window and clicked Submit, which gave me the message "Try harder..." From this I assumed that I would have to submit the right key in order to get a success message and hopefully the key for the challenge. So, now I wanted to disassemble the binary and see what happens when I click "Submit".

In IDA, the first thing I noticed is that most functions start with "\_\_T", which tells me I'm dealing with a Swift compiled binary, since that is the prefix for all symbols in Swift. Swift is great at making ugly, huge function names, so rather than messing around with demangling them or anything too ugly, I had one lead of the "Try harder..." string from when I entered a wrong key. I looked in the strings window and found references to that function and went back from there:

[![26](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/26-230x12.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/26.png)

Then I saw the same function both referencing the strings "Try harder..." and "C0ngr4tz!", so I knew I was on the right track. The function that references them looks like this:

[![27](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/27-230x435.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/27.png)

At the bottom where the code flow splits in two, each path has the same code with a different string reference, so I knew I was in the key check function. Now to figure out how to make it say "C0ngr4tz!"

Swift's compiler treats variables very similar to C++, passing a reference to "this" as an argument to functions, and then using it to find other class references. The class jump table for this class is NSViewController, found at 0x100008090. We'll need this in order to fix up the calls used in the function. After cleaning up all of Swift's object oriented code and Automatic Reference Counting (ARC), we can dumb this function down into some simpler pseudocode:

check\_key: a = entered\_key a = bb64(a) a = xxor(a, "av9vex8pocs4id2") a = bb64(a) a = xxor(a, " abracadabra") a = bb64(a) if a == " LyY8TiwwJighJzRSNycvJyU3LzQ1GTc0JlA2ACcGBTcuUSc3JBkZLSoaS1EzUwotBwsDDTQbEiY3Mw0SNDcZVjcLKywjCTpKPApWTw==": label = "C0ngr4tz!" else: "Try harder..."

|-------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | check\_key: a = entered\_key a = bb64(a) a = xxor(a, "av9vex8pocs4id2") a = bb64(a) a = xxor(a, " abracadabra") a = bb64(a) if a == " LyY8TiwwJighJzRSNycvJyU3LzQ1GTc0JlA2ACcGBTcuUSc3JBkZLSoaS1EzUwotBwsDDTQbEiY3Mw0SNDcZVjcLKywjCTpKPApWTw==": label = "C0ngr4tz!" else: "Try harder..." |

This gives us a pretty clear idea of what's going on, but we'll have to check each of these functions to figure out what they do. After analysis, we find that they do the following different functions:

* bb64 -- Base64 encode the passed in argument
* xxor -- XOR the passed string with the provided key

So, if we write a quick little python script, we can get the key:  
import base64 def xxor(plain, key): enc = "" for i in range(len(plain)): enc += chr(ord(plain\[i\]) ^ ord(key\[i % len(key)\])) return enc a = "LyY8TiwwJighJzRSNycvJyU3LzQ1GTc0JlA2ACcGBTcuUSc3JBkZLSoaS1EzUwotBwsDDTQbEiY3Mw0SNDcZVjcLKywjCTpKPApWTw==" a = base64.b64decode(a) a = xxor(a, "abracadabra") a = base64.b64decode(a) a = xxor(a, "av9vex8pocs4id2") a = base64.b64decode(a) print a

|-------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | import base64 def xxor(plain, key): enc = "" for i in range(len(plain)): enc += chr(ord(plain\[i\]) ^ ord(key\[i % len(key)\])) return enc a = "LyY8TiwwJighJzRSNycvJyU3LzQ1GTc0JlA2ACcGBTcuUSc3JBkZLSoaS1EzUwotBwsDDTQbEiY3Mw0SNDcZVjcLKywjCTpKPApWTw==" a = base64.b64decode(a) a = xxor(a, "abracadabra") a = base64.b64decode(a) a = xxor(a, "av9vex8pocs4id2") a = base64.b64decode(a) print a |

[![28](http://blog.paloaltonetworks.com/wp-content/uploads/2016/08/28-230x28.png)](https://blog.paloaltonetworks.com/wp-content/uploads/2016/08/28.png)

And the key is: PAN{My\_m0th3r\_told\_m3\_2b3\_w4ry\_of\_F@uns}

Leave a comment below to share your thoughts about the Unix track challenges. Be sure to also check out how other threat researchers solved these challenges:

**Unix Challenge 1**

* [https://irq5.io/2016/08/17/labyrenth-2016-write-up-bowie-pl/](https://irq5.io/2016/08/17/labyrenth-2016-write-up-bowie-pl/)
* [https://github.com/uafio/git/blob/master/scripts/labyREnth-2016/labyrenth-2016-unix-1.py](https://github.com/uafio/git/blob/master/scripts/labyREnth-2016/labyrenth-2016-unix-1.py)

**Unix Challenge 3**

* [http://www.ghettoforensics.com/2016/08/running-labyrenth-unit-42-ctf.html](https://www.ghettoforensics.com/2016/08/running-labyrenth-unit-42-ctf.html)

**Unix Challenge 5**

* [https://github.com/uafio/git/blob/master/scripts/labyREnth-2016/labyrenth-2016-unix-5.txt](https://github.com/uafio/git/blob/master/scripts/labyREnth-2016/labyrenth-2016-unix-5.txt)

**Unix Challenge 6**

* [http://www.ghettoforensics.com/2016/08/running-labyrenth-unit-42-ctf.html](https://www.ghettoforensics.com/2016/08/running-labyrenth-unit-42-ctf.html)
* [https://github.com/uafio/git/blob/master/scripts/labyREnth-2016/labyrenth-2016-unix-6.py](https://github.com/uafio/git/blob/master/scripts/labyREnth-2016/labyrenth-2016-unix-6.py)

**Unix Challenge 7**

* [https://github.com/uafio/git/blob/master/scripts/labyREnth-2016/labyrenth-2016-unix-7.txt](https://github.com/uafio/git/blob/master/scripts/labyREnth-2016/labyrenth-2016-unix-7.txt)

Back to top

### Tags

* [CTF](https://unit42.paloaltonetworks.com/tag/ctf/ "CTF")
* [LabyREnth](https://unit42.paloaltonetworks.com/tag/labyrenth/ "LabyREnth")
* [Unix](https://unit42.paloaltonetworks.com/tag/unix/ "Unix")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: VB Dropper and Shellcode for Hancitor Reveal New Techniques Behind Uptick](https://unit42.paloaltonetworks.com/unit42-vb-dropper-and-shellcode-for-hancitor-reveal-new-techniques-behind-uptick/ "VB Dropper and Shellcode for Hancitor Reveal New Techniques Behind Uptick")

### Related Articles

* [LabyREnth CTF 2017: Check Out the Prizes](https://unit42.paloaltonetworks.com/unit42-labyrenth-ctf-2017-check-out-the-prizes/ "article - table of contents")
* [LabyREnth CTF 2017 Winners!](https://unit42.paloaltonetworks.com/unit42-labyrenth-ctf-2017-winners/ "article - table of contents")
* [LabyREnth CTF 2017 Final Week: Beat the Maze!](https://unit42.paloaltonetworks.com/unit42-labyrenth-ctf-2017-final-week-beat-maze/ "article - table of contents")

## Related Cybersecurity Tutorials Resources

![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 1, 2024 [#### Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "Wireshark Tutorial: Exporting Objects From a Pcap")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) October 10, 2023 [#### Wireshark Tutorial: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/ "Wireshark Tutorial: Identifying Hosts and Users")  
  ![An abstract illustration of a video that has been paused. It includes a red progress bar and a large white Play button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/03_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 8, 2023 [#### Wireshark Tutorial: Display Filter Expressions](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/ "Wireshark Tutorial: Display Filter Expressions")  
  ![A person focuses intently on a screen, with many lines of code on the monitor reflected in their glasses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 1, 2023 [#### RedLine Stealer: Answers to Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/ "RedLine Stealer: Answers to Unit 42 Wireshark Quiz")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 31, 2023 [#### Wireshark Tutorial: Changing Your Column Display](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/ "Wireshark Tutorial: Changing Your Column Display")  
  ![Person wearing glasses and a hoodie, sitting in a dimly lit room, focused on a computer screen displaying complex data visualizations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/06_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 18, 2023 [#### Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/ "Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 30, 2023 [#### Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/ "Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID")  
  ![A woman is intently working on a computer in a modern office environment, surrounded by screens displaying dynamic digital data and stock market numbers, highlighting a focus on financial analysis.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 26, 2023 [#### Cold as Ice: Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/ "Cold as Ice: Unit 42 Wireshark Quiz for IcedID")  
  ![Two people working in a modern office environment with one person concentrating on a computer screen displaying code while another person works in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/10_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) May 15, 2023 [#### It's All in the Name: How Unit 42 Defines and Tracks Threat Adversaries](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")

* [Threat actors](https://unit42.paloaltonetworks.com/tag/threat-actors/ "threat actors")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/ "It’s All in the Name: How Unit 42 Defines and Tracks Threat Adversaries")  
  ![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 27, 2023 [#### Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/)

* [Gozi](https://unit42.paloaltonetworks.com/tag/gozi/ "Gozi")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/ "Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
