Magnet Weekly CTF Challenge Week 5 Writeup a.k.a. Fun with Hadoop
Another week (and month) has gone and the Magnet Weekly CTF Challenge has entered week 5. As announced by the CTF organisers, Linux images prepared by Prof. Ali Hadi would be used for November's CTF challenges and they could be downloaded from here.
The first November challenge question is not a long one, yet still an interesting one:
It is worth mentioning that the Linux images (3 in total, 1 HDFS primary and 2 HDFS secondary nodes) came from a "Hadoop Distributed File System" (HDFS) environment. Since the phrase "Had-A-Loop" rhymes with "Hadoop", it would be a no-brainer to look at the HDFS first.
Diving into the HDFS Storage
The HDFS primary node image was examined first. The Hadoop was installed under "/usr/local/hadoop/" directory and the HDFS data storage location was designated by the directory value in "dfs.datanode.data.dir" property in a "hdfs-site.xml", which could be found in the "/usr/local/hadoop/etc/hadoop" directory:
From this point, it was clear that the HDFS data was stored under the "/usr/local/hadoop/hadoop2_data/hdfs/datanode" directory. However, there was no data under the HDFS data node directory on the HDFS primary node image. Therefore, the HDFS secondary mode 1 image was examined to look for the HDFS data nodes.
Spotting the HDFS Data Node Block File
At this moment, the answer of this challenge seemed to be "sources.list".
Getting Back on the Right Track
With the support of log lines, I am very certain the answer should be "AptSource._COPYING_" and eventually became the first person to crack this week's challenge. To be honest, even though there was no bonus point awarded for being the 1st solver, it was still an enjoyable and pleasant moment for myself.
Tying Up All Loose Ends
I was still curious about the "._COPYING_" file extension as I have never seen this kind of file extension. Then this Hadoop Issues page explained that the "._COPYING_" file extension would be created when a file was copied from HDFS or local to another file system implementation. Perhaps the perfect answer should be "AptSource", after all.
Lessons Learnt
Observe, don't just see. What you see may not be the whole truth.
Coincidence?
Evernote featured in week 4 had an elephant on its logo, whereas Hadoop featured in week 5 also had an elephant on its logo. Perhaps there would be also an elephant on week 6?😎
Comments
Post a Comment