150 likes | 266 Views
CTF#3: Team Slayer...or lack thereof. Ryan, Brian, Austin. Overview. Flags Results ... Scott's behavior :( Takeaways. Flag #1 - 100 pts. “Hey” “Yeah” “You ever wonder why we're here?”. Flag #2 - 100 pts. 7Zip. Text File Containing Flag.
E N D
CTF#3: Team Slayer...or lack thereof Ryan, Brian, Austin
Overview • Flags • Results ... Scott's behavior :( • Takeaways
Flag #1 - 100 pts “Hey” “Yeah” “You ever wonder why we're here?”
Flag #2 - 100 pts 7Zip Text File Containing Flag “Tuuuuckkkerrr.... Tuuuuuckkkerrrr.... I'm the ghost of Church, and I've come back with a waaarrrrningg...”
Flag #3 - 100 pts • Text file with hidden stream • open from command line • notepad <file>.txt:hidden “Private Donut... that sounds like Private Biscuit!”
Flag #4 - 100 pts Properties -> Details tab “What do you want, Caboose” “I want a pony”
Flag #5 - 50 pts In a plain text file waiting for them for Bam "I'm telling you, it was 4 shots; like bam, bam, bam!" " Wait a second, that's only 3 bams." "(annoyed) Bam." for Pai "Oh, my God, that cake is huge! It's big enough to fit a person in it." "Why does the cake smell like baby oil? Oh God, where's Donut?!"
Flag #6 - 50 pts html file comment "Try some dance moves-Oh-you could do a musical number!" "Get off the radio Donut!"
Flag #7 - 50 pts Output from a simple c++ program "You're absolutely right. That sounds like Morris Code." "Um, excuse me sir. It's actually not Morris Code, it's Morse code, sir."
Flag #8 - 100 pts There is a file on the server with the md5sum of 7a7ae99be364e3435542fea5f3aff1ab. What is the file and where did you find it? PAI: file was /etc/bingo BAM: file was /etc/funnyblueguy
Flag #9 - 100 pts There is a flag hidden inside of a virtual partition. Find the partition, open it, and describe the flag. Needed to mount -o loop the following files to find flags PAI: /var/virtpart then flag was lopezflag BAM: /opt/virtpart then flag was texflag
Machines Destroyed • BAM successfully destroyed PAI's 2003 Server • Captured all flags • Destroyed without flags • PAI's XP by BAM • PAI's CentOs by ... PAI ? • Submission Server by Unknown ... Scott? • All incapacitation were 100 pts, except for the CentOS machines (500 pts)
PAI +100 -650 ------------- -550 Results • BAM +339 -350 ------------- -11 BAM wins....but still loses!!!!
Takeaways • Team's have gotten a lot better at defense! • Out of class competition made things more difficult • Less coordination • More realistic network setup • Varying IP's • Adding machines throughout kept teams engaged...we hope • Social Engineering really works!
Summary • Flags • Point Breakdowns • Failure...Learning