This year among the participants of Competitive Intelligence were not only the contest’s usual fans but also CTF teams, so we adjusted difficulty levels accordingly. In addition, we allowed team play on one condition: a person couldn’t participate both individually and as part of a CTF team. That is why we reached a mutual agreement to disqualify the player who scored most — azrael.
All the contests were revolving around the fictional state — United States of Soviet Unions. The Competitive Intelligence participants had to look for info about company employees with the USSU citizenship. Meantime the players were free to answer five various questions regarding five different organizations. Within one block, you could open new questions after answering the previous ones. (One team even managed to find the right answer using a brute force method, but failed to advance after that – they just didn’t have enough info.)
1. Find out dinner location of Bank of Snatch (snatch-bank.phdays.com)’s Chairman/Get any info you can on him.
You had to find all the info available about the Chairman of Bank of Snatch.
1.1. Get his email address.
It’s quite easy in the beginning, actually — just get the Chairman’s email. Google already did that for you — it cashed several pages of snatch-bank.phdays.com, including the one with financial documentation.
The document’s metatags distinctly show that the user Aldora Jacinta Artino has the email a_j.artino.bank@ussu-gov.org, which means that the Chairman, which goes under the name of Zenon Pavlos Economides, should have an email like this: z_p.economides.bank@ussu-gov.org.
Correct answers: 47
1.2. What is his domain account? (format: user:password)
Let’s make it a bit more challenging. This time you need to find the domain account — name and password. For our return players the task proves to be quite easy. If you send an email to the previously acquired address, you may find a not so subtle hint that the guy read it, which means it’s high time to try and get him click on the link you want.
Note: Chairman’s browser blocked non-standard ports for web traffic like 1337. So just stick to 80 or 8080.
After capturing the query, you will see that the email server included in the message the Referer header, which can be used to retrieve the account name and password: zenontrapeza:zenon123.
Correct answers: 17
1.3. Finally, find out the dinner place.
As the title says. At the moment we have his alias – zenontrapeza. Let’s ask Google again. You are literally two clicks away from discovering the Chairman’s account of FB, which will give you another lead: our man loves to use a certain tracker.
But something seems off. After performing some unsophisticated manipulations with URL and ID, you should be able to gain access to the Pavlos track file:
Finally, we got the track we need. But here is a tough one for you – there are no GPS coordinates in it, just the mobile phone operator’s base station ID. No problem. There is an amazing site called opencellid.org, which allows finding base station coordinates around the world.
Having obtained the coordinates, you just need to define the lunch break time (exclude Sunday) and find the restaurant’s name via the good ol’ opencellid — Boston Seafood&Bar.
Correct answers: 12
2. Get intel on MiTM Mobile (mitm-mobile.phdays.com)’s marketing director.
You are required to collect info on the marketing director of MiTM Mobile.
2.1. We have network capture from the director's laptop (https://mega.co.nz/#!34IEGYZa!Xowwo-UFTWMIfqfmiSPQXMWY0F7mySb-WtIxB3SVXWQ ). Can you find out where he received medical treatment?
So where did he get medical help? Traffic dump allows you to find not only the domain login name of one of the Positive Technologies employees, but also the query to the USSU search engine.
Judging from the banner and the Cookies parameters at http://ussu.phdays.com/search.php, the search engine uses the utmz tokens, just like Google. If you insert this data into the query to search.php, the context ad for a hospital pops up. Your next step is to look for a matching image, disregarding all the rest or even easier — just perform a search with the contacts from the picture. The correct answer is Rayville Recovery.
Correct answers: 13
2.2. Ok, now we know his email account. It is l_u.imbesi@ussu-gov.org - we need access (give us the email password).
Robots.txt files are often a hidden treasure of vulnerable scripts that should be kept safe from hackers, not search engines. This time is no different. There is a link to a bugged script for password recovery from the email restore.php. If you call a password reset in the debug mode — debug=On, you may discover that emails are sent via port 25 of the server. The server name can be found directly in the Host header.
This means that if you use netcat on port 25 and send a query with the Host header containing your IP address and domain name, port 25 will get an email indicating the current password (AQwr34%!9R^).
Bonus: There was also a possibility to search the email box and find some insider info in draft emails about text messages getting cheaper at 10:30 a.m, which means that around this time the MiTM Mobile stocks will be going up.
Correct answers: 4
2.3. We need to find something to blackmail him with.
Nobody managed to crack this nut, which is quite disappointing. Want to dig up some dirt on the guy? Go to his Google account! His email life might not be breathtaking, but his search history is another story:
As it turned out, the marketing director decided that cocaine was much more exciting than alcohol. Too bad, man. The correct answer is cocaine.
Correct answers: 0
2.4. Some competitors with gov support also want him in jail. Who is it?
This technically challenging task proved to be too much for our contestants since you first need to get an answer to the question before it. In the previous task, you could see that the director is regularly attempting to find annual reports of a certain Whoever company, which is located in the whoever.phdays.com domain. From here on it’s an easy ride:
Correct answers: 0
3. This time prepare the big guns. You are required to get info on the presidential administration (ussu.phdays.com)
3.1. Crawl all administration emails in order from a to z (format: <email>,<email>,<email>, ...)
The first task is easy-breezy: you just need to find out all email addresses at the Administration. Go to ussu.phdays.com/contacts.php.
You will see that there is the alias administration@ussu-gov.org for general requests.
In addition, the state department has an extra MX server.
It looks like the government doesn’t care too much about safety of their employees — all it takes is just a couple of queries to obtain all the emails of the administration group:
The correct answer is a_o.bozhidara@ussu-gov.org, d_b.bertil@ussu-gov.org, j_l.andrus@ussu-gov.org, j_t.zlata@ussu-gov.org
Correct answers: 19
3.2. Get all passwords, emails in order from a to z (format: <email>:<password>,<email>:<password>,<email>:<password>, ...)
From here on things start to heat up, as Google will not be able to do all the work for you. Sitemap.xml says that there is a certain file. Here it is http://ussu.phdays.com/_logs/access.log. After some carefully studying, you may find the following curious queries:
GET
/auth.php?action=getToken&id=26080&email=%61%5f%6f%2e%62%6f%7a%68%69%64%61%72%61%40%75%73%73%75%2d%67%6f%76%2e%6f%72%67
GET
/auth.php?action=checkToken&token=EShDVGIWwZSjS5I5BQbpDyWRNoFUzBOWNygG8j%2FYpbpZl7sGymRScloK%2Fddq9a6%2FAaSTXZedUHTkhONlvfd2kvB63E%2B6iqSjecSaQMRyQw1vzs5otj3%2BmP%2Fp%2BS1Xil%2BVqn7GZJPLgsgcXy4cLtcCsw%3D%3D
Seems like the administration employee first gets some token, then validates it. If you take a closer look on the validation process, you will find out that it is easily cracked with the good ol’ Padding Oracle attacks, which means that the token may be deciphered with a modest number of queries.
After only 256 queries, we may claim with a 99% certainty that the algorithm implementation can be attacked. Throw in another 10 000 queries — and the token goes down completely. But you will not need this many as the password is at the very end, which means it gets deciphered first.
Ok then, we got one password deciphered. Now what? Inserting the emails you got before that and sorting IDs consequently, we’ll get all four tokens for all users.
Sign into one of the email accounts via Google to find another piece of insider info on price fluctuations of company stocks.
The correct answer is a_o.bozhidara@ussu-gov.org:zhi37@1!,d_b.bertil@ussu-gov.org:bertiB3rt!,j_l.andrus@ussu-gov.org:Andrus331,j_t.zlata@ussu-gov.org:aata4444
Correct answers: 6
To those of you who are interested to find out more about Padding Oracle attacks, we suggest this article:
https://blog.skullsecurity.org/2013/padding-oracle-attacks-in-depth
Here are the slides about application protection from this and other attacks:
http://www.slideshare.net/kochetkov.vladimir/hdswasm-russianproofreaded
3.3. Hack into Mac OS of the Administration secretary and give us # of the document printed for the president 14/05/2015.
Hacking the secretary’s Mac OS is a no brainer. Especially, if the said secretory leaves clues in the email signature, likes to store important archives in repositories, and reuses the same password.
Take Chainbreaker for Win32 and decipher the keychain from the repository with the help of the email password. The document number is #125_42-19.501.
Treat yourself to some interesting info about “Promising quarterly reports for Choo Choo Roads (CHOO), Hacknetcom (HCKNT), and MiTM Mobile (MITM)” getting published on May 27 at 11 a.m.
Correct answers: 3
3.4. Now we need to get this document. Give us a project name mentioned in it.
It’s time to delve into the administration resources once again. If you use the hint and log in as d_b.bertil@ussu-gov.org, you will find an interesting address with anonymous access via FTP in Google Cloud Printers https://www.google.com/cloudprint. Among hundreds of documents, there lies the one you need – something about the Omnieye project.
It also contains some interesting info about future stock rates and “Black Thursday”.
Correct answers: 0
3.5. Finally, break into an iPhone of one of the administration employees. There was some secret meeting in April. Where?
The participants failed to get to this task. Otherwise, they could possibly restore access to icloud.com using an email, password, and token to reset 2FA, which could be found in j_l.andrus@ussu-gov.org. Then you just needed to find the note about a meeting in McDonalds on Pushkin Square.
Correct answers: 0
4. We need proof that the government controls Positive Times (ptimes.phdays.com)
The participants were required to gather evidence that the Positive Times media giant has been under the government’s thumb for a long time.
4.1. Get the journalist's (w_j.dom@ussu-gov.org) mobile number - he is a rat. Tip: he always uses two accounts for privacy in social networks. (format, no delimiters: +7xxxxxxxxx#xxxxxxx)
Once again, the first task turns out to be easy – just get the journalist’s phone number. He seems to be suffering from the multiple personalities syndrome — 2 accounts on VK.com and another 2 on FB.com. Find the first account using a password reset function on FB.com
Find the vk.com one comparing names in the lists of people who liked ptimes.phdays.com.
You may see that the only one who fits is a person at https://vk.com/id304632346. On his page, you will find the first part of his mobile number and his email.
If you try to restore the FB account with this email, you’ll see it’s the same guy.
Now, when you found his account via his FB email, take a look at the Details section, and you’ll see the missing part of the phone. The correct answer is +79652843472#317.
Note: We had to use “an extension number” to exclude any attempt to brute force it.
Correct answers: 34
4.2. Get access to the publishing engine of Positive Times. Give us user and password. (format: <email>:<password>)
Now you are required to gain access to the Positive Times portal admin panel. Let us guess. At sitemap.xml you found the list of emails reset passwords are sent to (the sentemails.log file), you even got an email with a token for password restoring, and changed password using the public inbox from the list ptimes-registration@mailinator.com. But this account doesn’t have a sufficient privilege level to do anything useful! Well, duh, what did you expect? Some shabby email box being used for administrative stuff? Dream on.
However, if you take a close look at the password restoring process, you just might the see the light at the end of the tunnel: at the last stage, the system checks the email again.
Why? What if we change the email to a more privileged one from sentemails.log, say, to ptimes@ussu-gov.org. Bingo! You receive an email with a correct password on Mailnator, and now can answer the question. As a bonus, you gain access to the admin panel with the account ptimes@ussu-gov.org:Pt1M3P@ss. Once inside, you may find out two things — the tax being raised and the government cherry picking companies.
Besides insider info, this interface gives you an opportunity to change the second piece of news (so that it would work in favor of those who play against the market). Then we would have gotten it published on the second day of the contest at 11:30. Alas, either we overestimated the participants, or the fictional news just got buried under thousands of useless requests sent in attempt to exploit nonexistent XSS and SQLi.
Correct answers: 13
4.3. Get access to the email account of another corrupt journalist. His email is mediagov@ussu-gov.org. Give us his password.
To accomplish this task, you just needed to notice the form http://ptimes.phdays.com/feedback.php and with the hint from Google to realize that you may somehow upload files to the feedbackupload folder. After uncommenting the upload file field in the form and uploading the empty file .htaccess, you could obtain the feedbackupload directory listing for 5 minutes.
After that, it would be a piece of cake to find the file uploaded-13-05-2015.docx owned by mediagov@ussu-gov.org in the directory and realize that all images were taken from https://188.166.78.21:443/. Following the MSF hint, use the Heartbleed exploit from the Metasploit pack (there were some other exploit options that would have worked as well , but not all of them) at the address and get the user password from the memory dump:
Also, don’t forget: https://www.acunetix.com/websitesecurity/Why-File-Upload-Forms-are-a-Major-Security-Threat.pdf.
The correct answer is P@S$W0_PD.
Correct answers: 1
4.4. We found a group of hackers called PositiveLeaks. They may help us in our business. Find their leader's name for us.
Here are Wikileaks the enthusiasts that are also trying to dig something up on Positive Times. Judging from their name, they should be at pleaks.phdays.com. Also, with this request:
POST /userPage HTTP/1.1
Host: pleaks.phdays.com
Cookie: PHPSESSID=rr47fgk7e2rckklqj5kgl4f6k5
Content-Type: multipart/form-data; boundary=---------------------------214580240818081871851160929598
Content-Length: 376
-----------------------------214580240818081871851160929598
Content-Disposition: form-data; name="template"
123%' union select null,null,text as content from templates where '1%'='1
-----------------------------214580240818081871851160929598
Content-Disposition: form-data; name="action"
createTemplate
-----------------------------214580240818081871851160929598--
you may gain access to news templates on the site to find the answer (Boris_The_Emperor) and another piece of intel.
Correct answers: 0
5. The stock exchange market financial director was incriminated, but there was no evidence. Help to get him in jail.
Finally, you need to help justice and throw in jail the stock market financial director.
5.1. His name is Prabhat SAVITR. First, we need to find what gov got on him. Find his case ID.
Sounds familiar to those who played Competitive Intelligence before. There is a relation between the case IDs and photo IDs, and you may get the photo ID of the guy you need thanks to the directory listing.
This time we added a salt to md5(id): just do your homework in the md5 public databases, and you’ll find it — Chipp37.
That means the answer must be case-id=md5(Chipp371337)= 8bc875dbed7b0ecd966bed3c8ec750fa
Correct answers: 39
5.2. There was no evidence that the financial director was at the crime scene. We can blackmail him if we know deviceid and iccid of his phone and SIM. Get them for us (format deviceid;iccid)
DeviceId may be easily found in the case documents. You may download them by entering the ID from the last task into the form http://ussu.phdays.com/getdocument.php. To get iccid, you need to google the deviceid substring. The correct answer is a94360c365ab38810639911d355103c86367d5ba;897019903020414671.
Correct answers: 3
5.3. Where is the director hiding now? We need to know the city.
Unfortunately, the players managed to get to this task only by the end of the second day, so no one was able to do it right. Yet there was one team who brute forced the answer. In reality, what we wanted you to do is to use XSS to penetrate the page’s DOM the victim visits all the time (with the help of the input data obtained in the previous challenge). From the logs it was obvious that he uses a 3G modem manufactured by some mystery firm named OiWei. Gain access to web pages on the modem located at 192.168.44.1 thanks to the headers Access-Control-Allow-Origin: * sent by the modem. This would allow to capture cellid and other data to find out the director’s location — Hamilton.
Correct answers: 1
5.4. As you know by now, the stock market has a backdoor for executives. Give us the private key (Private-MAC for proof would be enough)
Apart from the location, you may retrieve the stock market backend address from the modem. We hoped that it would be enough to exploit 0 day in PHP to bypass openbasedir and read the contents of the key in /home. But alas.
Correct answers: 0
Summary
51 participants were not able to answer a single question.
The first place went to djecka – he was the first one who managed to give right answers to 9 questions.
The top team was rdot — they cracked 12 tasks.
All the contests were revolving around the fictional state — United States of Soviet Unions. The Competitive Intelligence participants had to look for info about company employees with the USSU citizenship. Meantime the players were free to answer five various questions regarding five different organizations. Within one block, you could open new questions after answering the previous ones. (One team even managed to find the right answer using a brute force method, but failed to advance after that – they just didn’t have enough info.)
1. Find out dinner location of Bank of Snatch (snatch-bank.phdays.com)’s Chairman/Get any info you can on him.
You had to find all the info available about the Chairman of Bank of Snatch.
1.1. Get his email address.
It’s quite easy in the beginning, actually — just get the Chairman’s email. Google already did that for you — it cashed several pages of snatch-bank.phdays.com, including the one with financial documentation.
The document’s metatags distinctly show that the user Aldora Jacinta Artino has the email a_j.artino.bank@ussu-gov.org, which means that the Chairman, which goes under the name of Zenon Pavlos Economides, should have an email like this: z_p.economides.bank@ussu-gov.org.
Correct answers: 47
1.2. What is his domain account? (format: user:password)
Let’s make it a bit more challenging. This time you need to find the domain account — name and password. For our return players the task proves to be quite easy. If you send an email to the previously acquired address, you may find a not so subtle hint that the guy read it, which means it’s high time to try and get him click on the link you want.
Note: Chairman’s browser blocked non-standard ports for web traffic like 1337. So just stick to 80 or 8080.
After capturing the query, you will see that the email server included in the message the Referer header, which can be used to retrieve the account name and password: zenontrapeza:zenon123.
Correct answers: 17
1.3. Finally, find out the dinner place.
As the title says. At the moment we have his alias – zenontrapeza. Let’s ask Google again. You are literally two clicks away from discovering the Chairman’s account of FB, which will give you another lead: our man loves to use a certain tracker.
- http://sport.phdays.com/account/1045/
- http://sport.phdays.com/achive/1045
- http://sport.phdays.com/img/1045
- http://sport.phdays.com/img/1, which gave an error you could use to find the final URL —http://sport.phdays.com/kmls/track.kml?id=1045
Finally, we got the track we need. But here is a tough one for you – there are no GPS coordinates in it, just the mobile phone operator’s base station ID. No problem. There is an amazing site called opencellid.org, which allows finding base station coordinates around the world.
Having obtained the coordinates, you just need to define the lunch break time (exclude Sunday) and find the restaurant’s name via the good ol’ opencellid — Boston Seafood&Bar.
Correct answers: 12
2. Get intel on MiTM Mobile (mitm-mobile.phdays.com)’s marketing director.
You are required to collect info on the marketing director of MiTM Mobile.
2.1. We have network capture from the director's laptop (https://mega.co.nz/#!34IEGYZa!Xowwo-UFTWMIfqfmiSPQXMWY0F7mySb-WtIxB3SVXWQ ). Can you find out where he received medical treatment?
So where did he get medical help? Traffic dump allows you to find not only the domain login name of one of the Positive Technologies employees, but also the query to the USSU search engine.
Judging from the banner and the Cookies parameters at http://ussu.phdays.com/search.php, the search engine uses the utmz tokens, just like Google. If you insert this data into the query to search.php, the context ad for a hospital pops up. Your next step is to look for a matching image, disregarding all the rest or even easier — just perform a search with the contacts from the picture. The correct answer is Rayville Recovery.
Correct answers: 13
2.2. Ok, now we know his email account. It is l_u.imbesi@ussu-gov.org - we need access (give us the email password).
Robots.txt files are often a hidden treasure of vulnerable scripts that should be kept safe from hackers, not search engines. This time is no different. There is a link to a bugged script for password recovery from the email restore.php. If you call a password reset in the debug mode — debug=On, you may discover that emails are sent via port 25 of the server. The server name can be found directly in the Host header.
This means that if you use netcat on port 25 and send a query with the Host header containing your IP address and domain name, port 25 will get an email indicating the current password (AQwr34%!9R^).
Bonus: There was also a possibility to search the email box and find some insider info in draft emails about text messages getting cheaper at 10:30 a.m, which means that around this time the MiTM Mobile stocks will be going up.
Correct answers: 4
2.3. We need to find something to blackmail him with.
Nobody managed to crack this nut, which is quite disappointing. Want to dig up some dirt on the guy? Go to his Google account! His email life might not be breathtaking, but his search history is another story:
As it turned out, the marketing director decided that cocaine was much more exciting than alcohol. Too bad, man. The correct answer is cocaine.
Correct answers: 0
2.4. Some competitors with gov support also want him in jail. Who is it?
This technically challenging task proved to be too much for our contestants since you first need to get an answer to the question before it. In the previous task, you could see that the director is regularly attempting to find annual reports of a certain Whoever company, which is located in the whoever.phdays.com domain. From here on it’s an easy ride:
- Get api.php from robots.txt
- Fuzz api.php and use popping errors to guess the parameters. Find XXE and get all source codes with it.
- The results will indicate that there is the unserialize function in api.php, which gives us INSERT SQL-inj.
- After successful table insertion, call unserialize in index.php (database data goes to unserialize) and, finally, get RCE.
- Go to /home to find the email of the guy who owns Whoever, which is wh0wh0wh0ever@gmail.com.
Correct answers: 0
3. This time prepare the big guns. You are required to get info on the presidential administration (ussu.phdays.com)
3.1. Crawl all administration emails in order from a to z (format: <email>,<email>,<email>, ...)
The first task is easy-breezy: you just need to find out all email addresses at the Administration. Go to ussu.phdays.com/contacts.php.
You will see that there is the alias administration@ussu-gov.org for general requests.
In addition, the state department has an extra MX server.
It looks like the government doesn’t care too much about safety of their employees — all it takes is just a couple of queries to obtain all the emails of the administration group:
The correct answer is a_o.bozhidara@ussu-gov.org, d_b.bertil@ussu-gov.org, j_l.andrus@ussu-gov.org, j_t.zlata@ussu-gov.org
Correct answers: 19
3.2. Get all passwords, emails in order from a to z (format: <email>:<password>,<email>:<password>,<email>:<password>, ...)
From here on things start to heat up, as Google will not be able to do all the work for you. Sitemap.xml says that there is a certain file. Here it is http://ussu.phdays.com/_logs/access.log. After some carefully studying, you may find the following curious queries:
GET
/auth.php?action=getToken&id=26080&email=%61%5f%6f%2e%62%6f%7a%68%69%64%61%72%61%40%75%73%73%75%2d%67%6f%76%2e%6f%72%67
GET
/auth.php?action=checkToken&token=EShDVGIWwZSjS5I5BQbpDyWRNoFUzBOWNygG8j%2FYpbpZl7sGymRScloK%2Fddq9a6%2FAaSTXZedUHTkhONlvfd2kvB63E%2B6iqSjecSaQMRyQw1vzs5otj3%2BmP%2Fp%2BS1Xil%2BVqn7GZJPLgsgcXy4cLtcCsw%3D%3D
Seems like the administration employee first gets some token, then validates it. If you take a closer look on the validation process, you will find out that it is easily cracked with the good ol’ Padding Oracle attacks, which means that the token may be deciphered with a modest number of queries.
Ok then, we got one password deciphered. Now what? Inserting the emails you got before that and sorting IDs consequently, we’ll get all four tokens for all users.
Sign into one of the email accounts via Google to find another piece of insider info on price fluctuations of company stocks.
The correct answer is a_o.bozhidara@ussu-gov.org:zhi37@1!,d_b.bertil@ussu-gov.org:bertiB3rt!,j_l.andrus@ussu-gov.org:Andrus331,j_t.zlata@ussu-gov.org:aata4444
Correct answers: 6
To those of you who are interested to find out more about Padding Oracle attacks, we suggest this article:
https://blog.skullsecurity.org/2013/padding-oracle-attacks-in-depth
Here are the slides about application protection from this and other attacks:
http://www.slideshare.net/kochetkov.vladimir/hdswasm-russianproofreaded
3.3. Hack into Mac OS of the Administration secretary and give us # of the document printed for the president 14/05/2015.
Hacking the secretary’s Mac OS is a no brainer. Especially, if the said secretory leaves clues in the email signature, likes to store important archives in repositories, and reuses the same password.
Treat yourself to some interesting info about “Promising quarterly reports for Choo Choo Roads (CHOO), Hacknetcom (HCKNT), and MiTM Mobile (MITM)” getting published on May 27 at 11 a.m.
Correct answers: 3
3.4. Now we need to get this document. Give us a project name mentioned in it.
It’s time to delve into the administration resources once again. If you use the hint and log in as d_b.bertil@ussu-gov.org, you will find an interesting address with anonymous access via FTP in Google Cloud Printers https://www.google.com/cloudprint. Among hundreds of documents, there lies the one you need – something about the Omnieye project.
It also contains some interesting info about future stock rates and “Black Thursday”.
Correct answers: 0
3.5. Finally, break into an iPhone of one of the administration employees. There was some secret meeting in April. Where?
The participants failed to get to this task. Otherwise, they could possibly restore access to icloud.com using an email, password, and token to reset 2FA, which could be found in j_l.andrus@ussu-gov.org. Then you just needed to find the note about a meeting in McDonalds on Pushkin Square.
Correct answers: 0
4. We need proof that the government controls Positive Times (ptimes.phdays.com)
The participants were required to gather evidence that the Positive Times media giant has been under the government’s thumb for a long time.
4.1. Get the journalist's (w_j.dom@ussu-gov.org) mobile number - he is a rat. Tip: he always uses two accounts for privacy in social networks. (format, no delimiters: +7xxxxxxxxx#xxxxxxx)
Once again, the first task turns out to be easy – just get the journalist’s phone number. He seems to be suffering from the multiple personalities syndrome — 2 accounts on VK.com and another 2 on FB.com. Find the first account using a password reset function on FB.com
Find the vk.com one comparing names in the lists of people who liked ptimes.phdays.com.
You may see that the only one who fits is a person at https://vk.com/id304632346. On his page, you will find the first part of his mobile number and his email.
If you try to restore the FB account with this email, you’ll see it’s the same guy.
Now, when you found his account via his FB email, take a look at the Details section, and you’ll see the missing part of the phone. The correct answer is +79652843472#317.
Note: We had to use “an extension number” to exclude any attempt to brute force it.
Correct answers: 34
4.2. Get access to the publishing engine of Positive Times. Give us user and password. (format: <email>:<password>)
Now you are required to gain access to the Positive Times portal admin panel. Let us guess. At sitemap.xml you found the list of emails reset passwords are sent to (the sentemails.log file), you even got an email with a token for password restoring, and changed password using the public inbox from the list ptimes-registration@mailinator.com. But this account doesn’t have a sufficient privilege level to do anything useful! Well, duh, what did you expect? Some shabby email box being used for administrative stuff? Dream on.
However, if you take a close look at the password restoring process, you just might the see the light at the end of the tunnel: at the last stage, the system checks the email again.
Why? What if we change the email to a more privileged one from sentemails.log, say, to ptimes@ussu-gov.org. Bingo! You receive an email with a correct password on Mailnator, and now can answer the question. As a bonus, you gain access to the admin panel with the account ptimes@ussu-gov.org:Pt1M3P@ss. Once inside, you may find out two things — the tax being raised and the government cherry picking companies.
Besides insider info, this interface gives you an opportunity to change the second piece of news (so that it would work in favor of those who play against the market). Then we would have gotten it published on the second day of the contest at 11:30. Alas, either we overestimated the participants, or the fictional news just got buried under thousands of useless requests sent in attempt to exploit nonexistent XSS and SQLi.
Correct answers: 13
4.3. Get access to the email account of another corrupt journalist. His email is mediagov@ussu-gov.org. Give us his password.
To accomplish this task, you just needed to notice the form http://ptimes.phdays.com/feedback.php and with the hint from Google to realize that you may somehow upload files to the feedbackupload folder. After uncommenting the upload file field in the form and uploading the empty file .htaccess, you could obtain the feedbackupload directory listing for 5 minutes.
After that, it would be a piece of cake to find the file uploaded-13-05-2015.docx owned by mediagov@ussu-gov.org in the directory and realize that all images were taken from https://188.166.78.21:443/. Following the MSF hint, use the Heartbleed exploit from the Metasploit pack (there were some other exploit options that would have worked as well , but not all of them) at the address and get the user password from the memory dump:
Also, don’t forget: https://www.acunetix.com/websitesecurity/Why-File-Upload-Forms-are-a-Major-Security-Threat.pdf.
The correct answer is P@S$W0_PD.
Correct answers: 1
4.4. We found a group of hackers called PositiveLeaks. They may help us in our business. Find their leader's name for us.
Here are Wikileaks the enthusiasts that are also trying to dig something up on Positive Times. Judging from their name, they should be at pleaks.phdays.com. Also, with this request:
POST /userPage HTTP/1.1
Host: pleaks.phdays.com
Cookie: PHPSESSID=rr47fgk7e2rckklqj5kgl4f6k5
Content-Type: multipart/form-data; boundary=---------------------------214580240818081871851160929598
Content-Length: 376
-----------------------------214580240818081871851160929598
Content-Disposition: form-data; name="template"
123%' union select null,null,text as content from templates where '1%'='1
-----------------------------214580240818081871851160929598
Content-Disposition: form-data; name="action"
createTemplate
-----------------------------214580240818081871851160929598--
you may gain access to news templates on the site to find the answer (Boris_The_Emperor) and another piece of intel.
Correct answers: 0
5. The stock exchange market financial director was incriminated, but there was no evidence. Help to get him in jail.
Finally, you need to help justice and throw in jail the stock market financial director.
5.1. His name is Prabhat SAVITR. First, we need to find what gov got on him. Find his case ID.
Sounds familiar to those who played Competitive Intelligence before. There is a relation between the case IDs and photo IDs, and you may get the photo ID of the guy you need thanks to the directory listing.
This time we added a salt to md5(id): just do your homework in the md5 public databases, and you’ll find it — Chipp37.
That means the answer must be case-id=md5(Chipp371337)= 8bc875dbed7b0ecd966bed3c8ec750fa
Correct answers: 39
5.2. There was no evidence that the financial director was at the crime scene. We can blackmail him if we know deviceid and iccid of his phone and SIM. Get them for us (format deviceid;iccid)
DeviceId may be easily found in the case documents. You may download them by entering the ID from the last task into the form http://ussu.phdays.com/getdocument.php. To get iccid, you need to google the deviceid substring. The correct answer is a94360c365ab38810639911d355103c86367d5ba;897019903020414671.
Correct answers: 3
5.3. Where is the director hiding now? We need to know the city.
Unfortunately, the players managed to get to this task only by the end of the second day, so no one was able to do it right. Yet there was one team who brute forced the answer. In reality, what we wanted you to do is to use XSS to penetrate the page’s DOM the victim visits all the time (with the help of the input data obtained in the previous challenge). From the logs it was obvious that he uses a 3G modem manufactured by some mystery firm named OiWei. Gain access to web pages on the modem located at 192.168.44.1 thanks to the headers Access-Control-Allow-Origin: * sent by the modem. This would allow to capture cellid and other data to find out the director’s location — Hamilton.
Correct answers: 1
5.4. As you know by now, the stock market has a backdoor for executives. Give us the private key (Private-MAC for proof would be enough)
Apart from the location, you may retrieve the stock market backend address from the modem. We hoped that it would be enough to exploit 0 day in PHP to bypass openbasedir and read the contents of the key in /home. But alas.
Correct answers: 0
Summary
51 participants were not able to answer a single question.
The first place went to djecka – he was the first one who managed to give right answers to 9 questions.
The top team was rdot — they cracked 12 tasks.
1 | djecka | 1700 |
---|---|---|
2 | sharsil | 1700 |
3 | MZC | 1600 |
As I see that was so interesting quest! Participants could try the role of secret agents or detectives - and who didn't want to be a secter agent when he or she was a child?
ReplyDeleteThank you for posting!
Many thanks for sharing all details that the Competitive Intelligence participants had to look for info about company employees with the USSU citizenship. And it is must sharable post with sports students who come to seek dissertation writing help on various subject such as economics - http://www.dissertationhelp.uk/economics-dissertation/, nursing, finance, business and marketing from me as I am dissertation writer and working at Dissertation Help in UK. That’s why I am gratefully shared it with them. Keep sharing..!!
DeleteIt was a wonderful chance to visit this kind of site .custom essay writers and I am happy to know. thank you so much for giving us a chance to have this opportunity! I will be back soon for updates
ReplyDeleteUse imessage on windows
ReplyDeletevery interesting contest. thank you very much for this post where you illuminated it. it was wonderful
ReplyDeleteAdvertising is your main tool to have the business ready to go. Actually, everybody is busy in their company marketing over the World Wide Web. Unfortunately, online company is scammed with scammers. On occasion the provider hires you freelance, or occasionally it is a site designer which orders the copy google At an identical time, if you decide on the most suitable company having excellent reviews and reputation, you will enjoy well composed works.
ReplyDeleteWow, that's what I call the good post, which covers the problem from different sides! I saw similar posts only at SpeedyPaper.com before! But now I see that your blog is great too! I'll definitely read it whole.
ReplyDeleteDownload iMessage for PC
ReplyDeleteDD Vs CSK IPL Tickets: After a decade, IPL matches are still being loved by the entire cricket fans despite the fact that lot controversies get widespread across the nation. We all know that the battle between the teams is mainly said to be the IPL season
ReplyDeleteIPL Tickets in Delhi
The Tamilnadu Board of Secondary Education will be releasing the TN SSLC Result 2018 this May Month on its official organizational portal page
ReplyDeletewww.tnresults.nic.in
www.tnresults.nic.in 2018
Here is how to guide on iMessage for PC will help to every iMessage user. There are few steps that must be followed carefully.
ReplyDeletecreate an hotmail account
ReplyDeleteHotmail signup
Students and staff can access their hotmail email login using a web browser from anywhere with an internet connection.
ReplyDeleteThe Uttar Pradesh MadhyamikShikshaParishad (UPMSP) has clarified that the board students need not carry Aadhaar card along with admit cards to the test center.
ReplyDeletewww.upresults.nic.in
Use imessage on pc
ReplyDeleteview instagram profile picture
ReplyDeleteWelcome to the Best writer Review, Here you can get the best All Assignment Help review sites. We strongly urge you to check our entire website once and we will assure you will find this review website very useful. Our hard work will be rewarded if students like you will appreciate our effort and spread the message about this site with your class-fellows and friends.
ReplyDeletedownload instagram profile picture
ReplyDeleteThe game you've created is soo interesting. I would take part in such one if there was a possibility to do this again.
ReplyDeleteWowww! Very Nice Thanks For Sharing it. I like Your Blog Send Flowers To ITALY
ReplyDeleteGreat blog i like it send cakes to Islamabad
ReplyDeleteNice post i like it Send gifts to Pakistan .
ReplyDeleteGood one
ReplyDeletepick up lines
ReplyDeletepick up lines dirty
sexual pick up lines
best pick up lines
dirty pick up lines
very interesting information, I really like it because it can add insight for me more broadly, thank you very much for this extraordinary information instagram captions
ReplyDeletejiofi.local.html
ReplyDeletejiofi local html
jiofi login
http://jiofilocalhtml.net
Droid4x download
ReplyDeletedroid4x emulator
Droid4x App Download
ReplyDeleteWith many new updates to iMessage, many iPhone and other iDevice users want access to iMessage on the PC or workplace computers
download imessage apk
Thanks for the opportunity to comment under this post dude.
ReplyDeleteThanks for sharing the info, keep up the good work going.... I really enjoyed exploring your site. good resource
ReplyDeleteOh! This article has suggested to me many new information. I will embark on doing it. Hope you can continue to contribute your talents in this area. Thank you.
ReplyDeleteessay writing service
assignment writing service australia
Thanks for sharing this i got a lot of infojrmation from this... have you know about
ReplyDeletetank trouble 3 unblocked
We are a reputable writing company mental health argumentative essay topics of international experience with creation of different types of essays for students of all levels of education. We have a team of professional writers of all possible scientific areas. That is why our agency is always confident about our essays being of the top quality. The assignments we provide for our customers always contain relevant information and facts.
ReplyDeleteDue to a number of factors, the mental medicine is nowadays one of extremely popular scientific directions as long as scientists from all over the world explore the reasons for psychological problems, mental health argumentative essay, and the ways to overcome and treat them. People’s psychological peculiarities, behavior, and reactions to various factors and circumstances are under discussion and are carefully examined.
SD Game Hacker works perfectly fine on all offline games. However, in the case of online games, it may or may not work well in terms of hacking.
ReplyDeletefor more updates visit the official site
As soon as the filing season begins, salaried class are in a frenzy about taxes they must shell out for the said financial year. It is important to understand your tax slab and what each of your salary breakup component means.
ReplyDeletesave income tax
Really i appreciate the effort you made to share the knowledge. This is really a great stuff for sharing. Keep it up . Thanks for sharing. custom dissertation writing service
ReplyDeleteTea TV was initially launched on play store and its demand grew up within a year. Due to the free policy and low frequency of ads, it was greatly appreciated by all the public. Jasone is a team manager of Tea Tv app and he is explaining the official details and complete guidance.
ReplyDeleteWonderful Post. Thank you so much for sharing this!!. If you are looking for any custom dissertation writing service you can choose edubirdie illegal to get best custom dissertation paper at affordable price.
ReplyDeleteAs the survey page verifies the customer before taking the survey, it is evident that most of the people would prefer to access the page before visiting the restaurant on a regular basis.
ReplyDeletetelldunkinsurvey
telldunkin
shareit apk
ReplyDeleteshareit for android
shareit for pc
shareit for ios
shareit pc
That is why our agency is always confident about our essays being of the top quality.
This is to an extraordinary degree superb stuff for me. These days mechanical upgrades are fundamental in our lives. Thank for making such a decent site like Statistics Assignment Help I truly acknowledge for everything you've done here. I adore ur site and need to remain here for quite a while.
ReplyDeleteshareit install
ReplyDeleteshareit
shareit download
shareit app
These days mechanical upgrades are fundamental in our lives. Thank for making such a decent site.
I am very happy to read this. This is the kind of manual that needs to be given and not the random misinformation that’s at the other blogs. Appreciate your sharing this best posting. tik tok video
ReplyDeleteAcademic essay writing has been a parameter to judge the merits of the students for a long time. The present time is none the less. In fact, as time is passing by, students are having more and more requirements to write an essay that will be graded. Hence seeking academic essay help is on the rise and it will be.
ReplyDeleteEvery single student is searching for a proper essay generator who can understand the need of the work and do the essay completely flawless. However, it often happens that students fail to figure out who can be one of the best instant essay typer for their work.
Academic essay writing has been a parameter to judge the merits of the students for a long time. The present time is none the less. In fact, as time is passing by, students are having more and more requirements to write an essay that will be graded. Hence seeking Do my essay help is on the rise and it will be.
Get the best online homework help administrations assistance from the specialists of Students Assignment Help and at a low cost. Our industry master offers the dependable assignments administrations to the understudies. Our online master scholars are capable in finishing the task.
ReplyDeleteapple imessage for pc
ReplyDeleteGet help from Irelandassignmenthelp.com our company provides the Assignment Service. You take the assignment from here. It would be good for you to have good marks in your college. If you want to get ahead of your friends then you should hire our experts ireland assignment writers at affordable price in given time.
ReplyDeleteimessage for android
ReplyDeletethis post informative for us! thanks for sharing.
ReplyDeleteBusiness Law Assignment Help
All are saying the same thing, But it's a truth only. The post you have written is full of nice info. Keep on sharing!!
ReplyDeleteAngularjs Training in Chennai
Angularjs course in Chennai
Web Designing Course in chennai
PHP Training in Chennai
Hadoop Training in Chennai
AngularJS Training in OMR
AngularJS Training in Tambaram
Great Blog!!! Nice to read... Thanks for sharing with us...
ReplyDeleteembedded systems training in coimbatore
Embedded course in Coimbatore
embedded training in coimbatore
PHP Course in Madurai
Spoken English Class in Madurai
Selenium Training in Coimbatore
SEO Training in Coimbatore
Web Designing Course in Madurai
I was looking for someone from Australia as I needed a native writer who is well-versed with Australian English. Though there were many service provider from Australia, I chose australian help review because they specified that they have a ‘qualified team of writers, editors and researchers.’
ReplyDeleteTo get a better look at the customer experience of Edubirdie.com, you need to consider a few third-party reviewing platforms. There are plenty of them. Some of them have mixed reviews, while some are really harsh on the service provider. However, they all unanimously agree to the fact that Edubirdie.com is not as helpful as it claims it is.
Read more other service provider My assignment help review
Java Assignment Help
ReplyDeleteMany times students are tensed for their projects and assignments, so at that time they can take online assignment help to complete it on time. There are experts available online who prepare the perfect assignment for you. Assignment Help
great to read
ReplyDeleteInstagram Captions
what about your finances not bad but everything is just gorgeous Do you want to share with you how to make money sitting on the Internet come here crackajack online casino ratings list I wish you good luck earning head
ReplyDeletemake the medical bill payments online through quickpayportal
ReplyDeleteThis blog About Competitive Intelligence.thanks for sharing .
ReplyDeleteAssignment Help USA
My Assignment Services provides a 24-hour online Assignment Help and consultation to the students. Be it any subject such as Nursing, Economics, Law, Engineering, or Management, we provide the most reliable help with assignment online by our highly-proficient academic writers. My Assignment Services constantly aim to expand our base of assignment writing experts and call in international experts who are ex-professors from reputed business schools, management schools, engineering universities from across the globe. This provides you with an opportunity to get a global and world perspective in your Assignment Help UK answers and lets you connect with a writer who understands you. This company has been trusted by thousands of students in Australia for their incredible help with assignment that are provided to students worldwide. Join these thousands of students and achieve high distinction in each and every one of your college tasks. We are proud of our best assignment help experts because of their dedication towards providing continuous support to students by helping them meet deadlines and scoring better grades. We understand how important academic assessments are in developing a student's career and future opportunities, this is why we take extreme measures to ensure that all University Assignment Help solutions are best-in-class.
ReplyDeleteArticle! Written by you is full informative. Thanks.
ReplyDeleteI think my search of knowledge stops here. Your blog inspires me a lot. Assignment help
TutuApp APK is the Best iOS Helper to download free apps. Download TutuApp helper for Android, Windows, iPhone, iPad and get access to millions of apps.
ReplyDeleteI hope the information we share is useful and can be the best solution to cure your illness ... amen
ReplyDeleteObat Batuk Berdarah
Obat Jerawat Batu
Cara Mengobati Liver
Obat Luka Diabetes
Obat Tipes Anak
Great blog, thanks for sharing this.
ReplyDeleteManagement Assignment Help
Good job, dude always share these type of informative posts for us and community.
ReplyDeleteBest Candid Photographers in Bangalore
ReplyDeleteBest Candid Wedding Photographers in Bangalore
Pre Wedding Photography Bangalore
Candid Photography Bangalore
Candid Wedding Photographers in Bangalore
Pre Wedding Photographers in Bangalore
Best Candid Photographers in Bangalore
ReplyDeleteBest Candid Wedding Photographers in Bangalore
Pre Wedding Photography Bangalore
Candid Photographer in Bangalore
Candid Wedding Photographers in Bangalore
Wedding Photographer in Bangalore
I trust the data we share is helpful and can be the best answer for fix your disease.
ReplyDeleteBest Essay Writing Help Service USA
Bluestacks is the most widely used and downloaded Android Emulator which enables you to have an Android App running on your Windows PC or Laptop.
ReplyDeletethat's some top level hacking there. Love the intelligence.
ReplyDeletevudu watch free walmart
Thank you for sharing your post, that's so nice and interesting. I learn a lot from your ideas and the way you arranged them. Hope to see more posts on your blog.
ReplyDeleteoutlook email login
This is a very great post and the way you express your all post details that is too good. Thanks for sharing with us this useful post :
ReplyDeletepengobatan cacar air
manfaat sari kurma
cara mengobati batu empedu
If you are an Android Lover and Wants to Run your Android Apps & Games in Full-Screen PC Windows. Bluestacks App player is popular and top-rated Android Emulator in the world that enables to launch All android Application on Windows PC, Laptop and MAC. Its license is freeware & paid both you have to select your desired version from official webpage. Now here I will provide you Bluestacks app player link where you can download & installed its offline installer version on your PC windows.
ReplyDeleteBluestacks App Offline Installer
students assignment help offers NZ assignment maker service in which students can get help in their assignments from the experts of the New Zealand.
ReplyDeleteThanks a lot for sharing it, that’s truly has added a lot to our knowledge about this topic. Have a more successful day.
ReplyDeleteSEO Services Kerala
best proofreading service
Being an academic writer from the past 7+ years providing assignment online help to college and university students also associated with uaeassignmenthelp.com platform. Our experts have deep knowledge of assignment services. Our experts provide write my essay services in UAE.
ReplyDeleteThis Is Really Great Work. Thank You For Sharing Such A Good And Useful Information Here In The Blog binarytoday
ReplyDeleteNice to be visiting your blog again, it has been months for me. Well this article that i’ve been waited for so long. I need this article to complete my assignment in the college, and it has same topic with your article. Thanks, great share :
ReplyDeletecara mengobati kencing manis
cara mengobati gondok secara alami
myarrpmedicare
ReplyDeletemyaarpmedicare
myaarpmedicare.com pay bill
myaarpmedicareplans
myaarpmedicare dental
myaarpmedicare 2019
myaarpmedicare pharmacies 2019
myaarpmedicare.com 2019 provider directory
myaarpmedicare rx plans
myaarpmedicare formulary 2019
ReplyDeletemyaarpmedicare account
myaarpmedicare.com 2018
myaarpmedicare providers
myaarpmedicare.com drug list
myaarpmedicare.com register now
myaarpmedicare drug list 2019
myaarpmedicare vision
myaarpmedicare app
myaarpmedicare advantage
ReplyDeletemyaarpmedicare address
myaarpmedicare prior authorization form
myaarpmedicare find a doctor
myaarpmedicare.com advance directives
myaarpmedicare bill pay
myaarpmedicare benefits
myaarpmedicare com/rewards
myaarpmedicare com/id
myaarpmedicare com pay bill
ReplyDeletemyaarpmedicare complete drug list
myaarpmedicare.com 2018 provider directory
myaarpmedicare.com/rewards 2018
myaarpmedicare.com register
myaarpmedicare.com providers
myaarpmedicare.com drug list 2019
myaarpmedicare.com/rewards 2017
myaarpmedicare.com gift card
ReplyDeletemyaarpmedicare.com healthsafe id
myaarpmedicare.com health and wellness
www.myaarpmedicare.com hospitals
myaarpmedicare.com/pharmacy directory
myaarpmedicare.com formulary list 2019
Get SingaporeAssignmentHelp.com essay experts to complete your essay assignment before your time out. You can write any time assignment with the support of our expert academic writers.
ReplyDeleteNice post. Thanks for sharing! I want people to know just how good this information is in your article. It’s interesting content and Great work.
ReplyDeleteThanks & Regards,
VRIT Professionals,
No.1 Leading Web Designing Training Institute In Chennai.
And also those who are looking for
Web Designing Training Institute in Chennai
SEO Training Institute in Chennai
Photoshop Training Institute in Chennai
PHP & Mysql Training Institute in Chennai
Android Training Institute in Chennai
1337x
ReplyDeleteWonderful article always written with full planning and keyword research, whereby readers can clear their all doubts in single article also search engine wants same thing. Same as you can also check here free offline games for your android mobile and enjoy your day.
ReplyDeletemedicare denial remark codes
ReplyDeletemedicare deductible 2016
medicare denial code n793
medicare denial code co 151
medicare data
medicare denial reason codes pdf
medicare diagnostic centre
You are sharing such a nice stuff..All the replays share with you in hd. ofw pinoy tmabyan
ReplyDeleteThanks for sharing great info … Hiring a limousine are excellent option to make your special occasion more delightful. Limo Hire Melbourne – Hummer Hire Melbourne.
ReplyDeleteWhat a pleasant read! Very resourceful. Loved it. I look forward to reading more on this from you. Keep writing… And keep inspiring.
ReplyDeletepeople actually believe in astrology?
Whether you are shopping online or in store, using coupon sites can save you money. Here are the best coupon websites to save the most forever 21 coupons
ReplyDeleteReading your blog has been a great experience. It is very informative and useful. I personally loved it. I shall definitely recommend it to all my friends.
ReplyDeleteWhen Will Windows 11 Launch?, feel free to drop by on our page and check out our product.
https://storeindonesian.blogspot.com/ Indonesia
ReplyDeleteyoutube.com
Indonesian
Service HP
Best Online Store Indonesia
Komponen
Kursus
Jual Beli
Those are useful information for me, http://ung dung ngon thank you
ReplyDeleteLifelock Phone Number
ReplyDeleteCanon Printer Help Number
HP Printer Technical Support
Brother Printer Customer Care Phone Number
Several reviews have shown that the assignments lack adequate content necessary for their academic work.
ReplyDeleteMy Assignment Help Review shows a good content, lack of finesse and good service offered by myassignmenthelp as shown by student reviews. The different aspects where the service got good and poor reviews are discussed, to give an understanding why students should opt for this service.
Every student has agreed that edubirdie.com is involved in scam as it fulfills all the promises that are made.
Aspect that has made ukessays review a reliable service provider is that they always send the assignments prior to the due dates.
Check out our customer feedback, and see for yourself the value in purchasing from our store.
ReplyDeleteI think the information you share is very reasonable. At the very least, it was able to help me solve my problem. Thanks for sharing them, it helps me a lot. download lagu mp3
ReplyDeleteWhile I was pondering this blog, I could understand the actual responsibilities of an assignment provider. It is way more than just doing assignments. Just like the assignment experts of Online Assignment Expert do not close the case, until the student is fully satisfied, an assignment expert must ensure the same. Also, they must not compromise with the quality of assignments, at any cost!
ReplyDeleteAs a nursing student, I am totally satisfied with the quality of assignments that I’m being provided with, by the Online Assignment Help Experts.
Competitive Intelligence Writeup is nice information..It trigger me to put comment. melbourne limo hire | black limousine hire
ReplyDeleteThis comment has been removed by the author.
ReplyDeleteAmazing blog with the latest information. car hire melbourne airport | car rentals melbourne
ReplyDelete
ReplyDeleteimessage for pc windows 10
imessage for pc
imessage on windows 10
This comment has been removed by the author.
ReplyDeleteThe experts to solve my assignment team knows and understands the value of the academic deadlines in the student’s life. The team of AssignmentHelpShop.com is composed of 3000 plus academic experts.
ReplyDeletewebsite for best iso rom you can download here
ReplyDeletesuper smash bros brawl iso for best pc game you can download here
ReplyDeleteMario party 4 Gamecube iso Free Download for best pc game you can download here
Super Mario Galaxy 2 for best pc game you can download here
ReplyDeleteocean of pc games for best pc game you can download here
Gta 5 Pc game Free download Full version Highly Compressed you can download free gta 5 small setup
ReplyDeleteTekken 3 Game Download For Pc Window 7 for best pc game you can download here
This was a great read! You can refer this one of the best tarot card reading apps is Tarot Life.
ReplyDeleteTo ease services,we avail web portal for pre written research papers services where US students make “write my essay” “write my research paper” and “write my paper” requests.
ReplyDeleteStudents should ensure that quality of essays offered match their prices. All quality custom essay should ensure that customers’ private details are kept in privacy. This also applies when one needs pre written research papers.
ReplyDeleteWe are among the best online companies providing affordable custom research paper writing services. When you cheap essay writing service USA and buy nursing essays online you get the services of experts and specialists in your field.
ReplyDeleteAs the name suggests at Exoticar you will find the most luxurious and exotic range of cars for hire. Our area of expertise is providing wedding limousine hire.
ReplyDeleteWe are leaders when it comes to providing limo hire. Our wide collection of cars includes Mercedes Benz, Merc limo and Porsche limo and many more. Our team makes a sincere and honest effort to make your special day memorable.
With us you can assured that you are being provided with the best quality of vehicles that are completely comfortable and safe. Thus, the next time you think limo think Exoticar!
Our services and service areas include the following:
-Limo Hire Melbourne
-Limousine Hire Melbourne
-Wedding Car Hire
-Wedding Limousines
-Wedding Limo Hire
-Chrysler Limousine Hire
-Stretch Limo Hire
-Porsche Limo Hire
Thus with us superior quality of service meets the best cars and the result is a memorable wedding day for our clients. To know more about our services or to book a service give us a call or visit our website Exoticarhire.com.au
Best Limo Hire Melbourne
https://www.exoticarhire.com.au/
Limo Hire Melbourne, Wedding Limo Hire Melbourne
Melbourne has the best Limousines services in the world and boast about the most luxurious and exotic range of Limousines.
If you are visiting Melbourne, you must try the Limousine services ranging from Merc limo and Porsche limo and many more. Having a night out in a Limo with friends doesn't feel anything less than Hollywood movie.
Euro Taxi provide the best luxury chauffeur car services in and around Melbourne.
ReplyDeleteWe pride in providing the services like:
-Premium Silver Service Taxi Melbourne
-Luxury hotel transfers Melbourne
- Luxury Airport Transfer Melbourne
-Ride share Melbourne
-Corporate airport cars Melbourne
-Corporate Taxi Melbourne
-Luxury Hotel Transfers
Call us at 1300 387 682 or visit Luxury Hotel Transfers
An overwhelming web journal I visit this blog, it's unfathomably amazing. Unusually, in this present blog's substance made inspiration driving truth and reasonable. The substance of data is enlightening
ReplyDeleteOracle Fusion Financials Online Training
Oracle Fusion HCM Online Training
Oracle Fusion SCM Online Training
You attain full value for the money which you put in to access when you seek the services of our research paper writing company, as well as other types of best assignment writing service from our firm which include dissertations, theses, reviews any different writings.
ReplyDeleteWe are one of the nursing essay writing service company as we submit our papers on time and students will have a satisfactory time to go over the essay trying to counter check for any mistake or error which might need urgent correction. Order a custom assignment help and get the best results.
ReplyDeleteBigg Boss Vote
ReplyDeleteBigg Boss Tamil Vote
http://biggbossvote.blog/bigg-boss-vote/
Bigg Boss Vote
Bigg Boss Telugu Vote
http://biggbossvote.blog/bigg-boss-telugu-vote/
I feel it interesting; your post gave me a new perspective! I have read many other articles about the same topic, but your article convinced me assignment help Fujairah
ReplyDeleteGreat blog!!! The information was more useful for us... Thanks for sharing with us...
ReplyDeletePython Training in Chennai
Python course in Chennai
Python Classes in Chennai
Python Training Institute in Chennai
Pyhton training in Adyar
Python Training in Tnagar
Big data training in chennai
Hadoop training in chennai
Digital Marketing Course in Chennai
Selenium Training in Chennai
More impressive blog!!! Thanks for shared with us.... waiting for you upcoming data.
ReplyDeleteSoftware Testing Training in Chennai
software testing course in chennai
testing courses in chennai
software testing training institute in chennai
Software testing training in Thiruvanmiyur
Software testing training in Velachery
Python Training in Chennai
Digital marketing course in chennai
Python Training in Chennai
JAVA Training in Chennai
I would definitely thank the admin of this blog for sharing this information with us. Waiting for more updates from this blog admin.
ReplyDeleteData Science Course in Chennai
Data Science Training in Chennai
AWS Training in Chennai
Azure Training in Chennai
Cloud Computing Training in Chennai
VMware Training in Chennai
Data Science Training in Velachery
Data Science Training in Tambaram
Data Science Training in Adyar
Great information.
ReplyDeletecheck pc software's
Offline installers
Crucial content.
ReplyDeleteAndroid Store
Great job. Keep it up.
ReplyDeleteHere I am sharing a very useful resource for students looking for assignment help. ProAssignmentHelp providing all sort of assignment writing in various subjects like as : Electrical engineering assignment help , electronics assignment help , MATLAB assignment help , management assignment help , etc.
ReplyDeleteYou did a good job by adding details of competitive intelligence here...
ReplyDeleteYou are looking for nearest fuel locator ot 24 hour open fuel locator or nearest gas station by help of your smartphone then you must download app or checkout website Gas Station Near Me to find out gas station close to you. You want to find closest gas stations open at night then you must go with 24x7 open gas station. Checkout the which is company's gas stations is available to close you.
Thanks for sharing this
ReplyDeleteWe provide assignment help Melbourne. The teams of professional experts makers at Australiaassignmenthelp.com are working to provide the high language assignment help service online for all the high school or university students.
ReplyDeleteHere I am sharing a very useful resource for students looking for assignment help. ProAssignmentHelp providing all sort of assignment writing in various subjects like as : Electrical engineering assignment help , electronics assignment help , MATLAB assignment help , management assignment help , etc.
ReplyDeleteLooking for best English to Tamil Translation tool online, make use of our site to enjoy Tamil typing and directly share on your social media handle. Tamil Novels Free Download
ReplyDeleteThis is a great post with lot of information. we are provide Assignment writing help in low cost
ReplyDeleteThanks
Great work...Well explanation for this topic, it was really informatical for me and thanks for sharing. Keep updating...
ReplyDeleteLinux Course in Chennai
best linux training in chennai
Spark Training in Chennai
Oracle Training in Chennai
Oracle DBA Training in Chennai
Power BI Training in Chennai
Corporate Training in Chennai
Tableau Training in Chennai
Linux Training in T Nagar
Linux Training in Velachery
If you have been wondering who will “Affordable Research Paper Writing Service Online”“write my research paper” or “write my paper” choose us today and avoid poor grades.We reliably provide services at the stated price without hidden charges. Contact us and let us help you at any stage of your Affordable Essay Writing Services.
ReplyDeleteThe blog you shared is very good. I expect more information from you like this blog. Thankyou.
ReplyDeleteWeb Designing Course in anna nagar
Web Designing Course in chennai
Web Designing Course in OMR
Selenium Training in anna nagar
Software testing training in T Nagar
Web Designing Course in T Nagar
DOT NET Training in OMR
Tally Course in anna nagar
This comment has been removed by the author.
ReplyDelete
ReplyDeleteExcellent post gained lots of information here. Keep posting like this
Data Science Training in Velachery
Data Science Training in Tambaram
Data Science Training in Anna nagar
Data Science Training in OMR
Data Science Training in Adyar
Data Science Training in Vadapalani
Data Science Training in Porur
Data Science Training in Thiruvanmiyur
Data Science Training in T nagar
All our writers understand Assignment Writing Help standards, and they are always ready to work for you. Students can Research Papers Help in any field and on any level of education.
ReplyDeleteNice work. I loved it. Get free love tarot reading online accurate predictions easily with Tarot Life. Try it now.
ReplyDeleteThis comment has been removed by the author.
Deleteautoroot tools is best place to root your android device.
ReplyDeletehttps://aptoideapkdownload.co/autoroot-tools/
We understand that students in Australia encounter different challenges in completing their Best Custom Essay Writing Service. We offer Best Online Paper Writing Service to students regardless of their specialty, discipline or educational level.
ReplyDeleteWe are prepared to deliver reliable and trusted Write My Research Papers services in all the outlined levels of study due to the many experts that we have in our company. Our College Research Paper is affordable and cheap as well for students who have very limited cash flows, and their budgets are usually constrained.
ReplyDeleteCCleaner file hippo free download
ReplyDeleteOne of the things that you will realize is that our company offers custom Assignment Help Online that are similar to what you desire for you to improve your grade. Our writing urgency has specialized in offering Research Paper Writing Service services, and we have been in the industry for a decade.
ReplyDeleteGet instant access to a huge number of apps, games for Android, Windows, and Mac operating systems. And also the latest news, trending topics, tech and culture Download apps & games from Earnigo.
ReplyDeletehttps://earnigo.com/
https://earnigo.com/tech/facebook-alternatives/
facebook alternative
facebook alternatives
facebook app alternative
Our top-notch writers have access to peer-reviewed articles, Free Essay Writer Services and online databases that are essential in writing Custom Writing Services on any chosen topic.
ReplyDeleteThe writers who write our Research Paper Services writers are experts,and they have sufficient experience to enable them to provide a high-quality paper that will help the student score high grades. We do not only write Term Papers Writing Services for students but also help and teach them how they can write one by themselves.
ReplyDeleteOur top-notch writers have access to peer-reviewed articles, Essay Writer Services and online databases that are essential in writing Best Custom Writing Services on any chosen topic.
ReplyDeleteThanks for the sharing this useful stuff you can also find more interesting tips on wackyfreaky.com Even, many people are already updated their existing knowledge by reading blog from wackyfreaky. At this time sharing about most popular software download websites list and enjoy free downloading.
ReplyDeleteDo you need help with business Economics assignment writing? Today, availing online Economics assignment help has become easier than ever before. Get instant help from Economics assignment expert for more visit Myassignmenthelp.com.
ReplyDeleteThanks for sharing. Top seo company in india
DeleteAccording to a new UPSC notification, candidates who wish to apply ... present the EWS? UPSC reservation certificate when asked,
ReplyDeleteWow! What an informative blog it was. It actually gave me an insight into the working of a genuine assignment expert. I got to know that the work of an assignment provider is not just limited to providing reference quality assignment solutions, but stretches way beyond than this. It also concerns never letting any of the queries of students go unsolved. This is exactly how the assignment help Adelaide experts at My Assignment Services work.
ReplyDeleteThe assignment expert team here is a panel of erudite academicians who not only work upon guiding students on every core concept related to the assignment, but also provide a wide range of value-added services that serve all the purpose of students. These also include the newly launched value-added services such as the newly launched mobile application, immediate grievance handling by client satisfaction manager and more. This is the reason their assignment help Melbourne team is known as the most reliable crew of experts.
Thanks for sharing. Keep it up. Colour Powder Festival
ReplyDeleteThanks for sharing. Best seo company in India
ReplyDeleteThanks for sharing. Keep it up. Colour Powder For Color Run
ReplyDeleteGood information and, keep sharing like this.
ReplyDeleteCrm Software Development Company in Chennai
The companies in UAE registered under VAT will be required to prepare formal tax returns on regular interval. According to the Ministry of Finance, it is likely that there will be an online filing of the reports. For more visit: Vat Compliance Requirement, Vat Registration Price
ReplyDeleteAjmer city various hotels and motels provide traveler an experience of Rajasthan with safety and security. There are lots of economy budget hotel in Ajmer. This time sharing about most popular software download websites and enjoy free downloading.
ReplyDeleteI read the article, this is awesome. Keep updating interesting articles. I am offering statistics assignment help, economics assignment help and finance assignment help to students over the globe at very affordable prices.
ReplyDeleteWe are following your website posts.
ReplyDeletePlease keep on posting and sharing great ideas.
Dentists Red Deer
Good Information keep going.
ReplyDeleteYouTube Marketing Company in Chennai
Nice information.
ReplyDeleteSeo Company in Chennai
Outstanding blog with lots of information. Keep posting more like this.
ReplyDeleteEthical Hacking course in Chennai
Ethical Hacking Training in Chennai
Hacking course in Chennai
ccna course in Chennai
Salesforce Training in Chennai
AngularJS Training in Chennai
PHP Training in Chennai
Ethical Hacking course in Tambaram
Ethical Hacking course in Velachery
Ethical Hacking course in T Nagar
Keep posting great insights.
ReplyDeleteHome Inspection Hamilton Ontario
Nice information keep sharing like this.
ReplyDeletescaffolding dealers in chennai
Aluminium scaffolding dealers in chennai
Aluminium scaffolding hire
Good information
ReplyDeletesecurity agency in chennai
best security service in chennai
Nice post.
ReplyDeleteSmm company in Chennai
It’s good to share information with others. I am also sharing something very important for students seeking MATLAB Assignment Help. Visit MatlabSolutions and get best assistance in your MATLAB, Simulink Assignments and Projects.
ReplyDeleteYou can also get CDR Report Engineers Australia if you look to immigrate to Australia.
ReplyDeleteSEO Agency India is one of the top digital marketing agency in India. As an Internet marketing agency, we are specialized in SEO, PPC, SMO, SMM, and SEM.
Keep on sharing this wonderful ideas.
ReplyDeleteConcrete Saskatoon Contractors
I really like and recognize your website post.
ReplyDeleteFurnace Repair Service Saskatoon
At Justquestionanswer.com experts are ready to provide you online Economics assignment help . The best team of masters and Ph.D. degree professionals that understand student’s demands and complete the task properly. Our experts of native writers from the USA.
ReplyDeleteThanks for sharing such informative post. Limousine king offer luxury Limo Hire Melbourne at affordable price. We always committed to treat you like royalty. Limo Hire Melbourne Prices
ReplyDeleteThanks for the post. Air Conditioning Red Deer Contractors
ReplyDeletePh.D is one of the biggest degree among the all other degrees. For this purpose, we have to clear 18 years of education and then we get admission for Ph.D. After passing this examination, we can get a good job. A number of students of Buy Dissertation Online have passed Ph.D exams and doing jobs in different departments.
ReplyDeleteMobile app development company in gurgaon
ReplyDeleteشركة الصفرات لرش الحشرات الرياض شرق وغرب الرياض
ReplyDeleteشركة الكشف عن تسرب الحمامات الظهران
شركة الكشف عن تسربات الحمامات الاحساء
You have a good looking web site.Your web page is great.
ReplyDeleteAuto Detailing Red Deer Ab
Thanks for sharing excellent article. Limousine king offer luxury Limo Hire Frankston at affordable price. We always committed to treat you like royalty. Limo Hire Mornington Peninsula
ReplyDeleteAre you looking for Unmatched Pre Written Research Paper? You don’t need to fail your Top Rated Nursing Writing Services when you can utilize the best Dissertation Help Services or Buy Pre Written Research Papers from the help of the online paper writers.
ReplyDeleteYour page looks wonderful!
ReplyDeleteCarpet Cleaners Kitchener
Best piece of info ever looking forward for more, If you are looking for a way to remove the lingering odors from your living space, office or in your commercial premises then you are in the right place. Get one from Best Ozone Generator
ReplyDeleteThis is additionally a generally excellent post which I truly appreciate perusing. It isn't regular that I have the likelihood to see something like this.
ReplyDeletelive forex signals
free forex signals
forex signals daily
Your page looks wonderful, it's great and full of infos.Keep it up!
ReplyDeleteRed Deer Furnace Cleaning
Criminology Paper Writing Services are the leading ones in the industry, being specialists in Criminology Research Paper Services enabling you to achieve profound success in your endeavors and on your Custom Criminology Assignment Writing Services tasks.
ReplyDeleteAt My Assignment Help we have a number of service’s that we have to offer, among them my assignment help is one of the most in demand service that majority of the students inquire about.
ReplyDeleteGood work! I enjoyed reading the article.
ReplyDeleteGarage Door Repair Near Me
Buy Research Papers Online provide 100% top-quality Buy Non-Plagiarized Research Papers for all their Custom Research Paper Writing Services levels.
ReplyDeleteNice to see your blog Topxlisting
ReplyDeleteEasy language is very important to write an article or blog, these all thing, I can get in your article. I am very glad about your writing article, lots of thanks, I would like to inform you about the online assignment help cheap to make the assignment quickly. online assignment help cheap
ReplyDeleteAll Academic Book Review Writing Services shall deliver your Buy Essay Online Services on time without compromising on the Buy Dissertation Papers Online quality.
ReplyDeleteAmazing article! Thanks for sharing. Are you searching for the most reliable writing service? Nursing Assignment Help is a trustworthy and excellent writing service, they are skillful and expert writers so you no need to search more anywhere when you reach them.
ReplyDeleteSuperb article! Thanks for sharing. Are you searching for the most reliable writing service? Nursing Assignment Help is a trustworthy and excellent writing service, they are skillful and expert writers so you no need to search more anywhere when you reach them.
ReplyDeleteAmong the most popular Psychology Papers Writing Services provided to students is High Quality Psychology Papers intended to meet your academic needs, as well as Psychology Research Paper Writing.
ReplyDeleteThanks for keeping people up on what's happening.
ReplyDeleteSaskatoon Eavestrough
I have inspected your blog its associating with and essential. I like it your blog.
ReplyDeleteBest PPC Company In India
pay per click advertising services
ppc campaign management services
ppc marketing company
ppc management services
MyAssignmentHelp has an exceptional panel of professional, expert writers from all over Australia, UK and etc. MyAssignmentHelp is the leading online assignment help service that have been successfully serving the students of Australia from a couple of years now.
ReplyDelete
ReplyDeleteJeewangarg is a Leading Digital Marketing Company which is helping your brand to cut through the Digital Clutter with its best SEO Company in Delhi. Our range of Services includes SEO Services, PPC Company in Delhi, Website Designing Services and Social Media Marketing Services. Being a Google Partners Agency we provide our client with 100% satisfaction in every aspect of their marketing goals. So, what are you waiting for Connect to the team of best SEO Expert India, Google Ads Experts, Website Designing Experts, Social Media Experts & more to boost your Digital Presence today with the high quality Digital Marketing Services.