We had a small break with our hacking challenges Redo. The format of the Meetup required a change, to accommodate for less experienced visitors. And as much as I love the SANS Institute Challenges, they tend to be quite a puzzle, especially later one. So for now, we are going to focus on couple other Hacking Challenges that are available online. And hopefully in December, when new 2022 SANS Hack Challenge starts, we will have a group ready to battle it together 🙂
Let’s start from Over the Wire. There are plenty games there, we will start with the Bandit, as most suitable to get used to the platform. Bandit offers 33 levels to play, it teaches Linux commands and tools. In each level your goal is identical, find a password to the next level, but let’s start from the beginning.
To play Bandit you will need to establish SSH connection to the Over the Wire lab server, all details of connection are given in Level 0.
So, what is SSH?
Secure Shell, sometimes referred to as Secure Socket Shell, is a protocol which allows you to connect securely to a remote computer or a server by using a text-based interface. When a secure SSH connection is established, a shell session will be started, and you will be able to manipulate the server by typing commands within the client on your local computer. System and network administrators use this protocol the most, as well as anyone who needs to manage a computer remotely in a highly secure manner.
How to use SSH on Windows?
Most common ways of using SSH on Windows is by using one of the clients. Most popular clients are: PuTTY, BitwiseSSH and OpenSSH. Windows 10 users have now the option to use build-in OpenSSH client. Just follow the installation details of your choose client.
How to use SSH on Mac?
Mac’s have build-in Terminal feature, that provides SSH client.
How do we do it on Linux?
That shouldn’t be a problem for any regular Linux users, but in case you are just starting with Linux. Go to your terminal and type:
This should list all ssh details and commands. If that’s not the case, just use the following command to install OpenSSH:
This post will summaries last Meetup progress and provides clues for further steps.
Let’s start we the recap. We started with:
Followed shortly by:
On the 23rd of January Meetup we have completed following tasks:
Objective 1 – Uncover Santa’s Gift List – clues in blog post video above
Objective 2a – Kringle Kiosk – clues in blog post video above
Objective 2b – S3 bucket – clues give at a Discord were: update the wordlist and add the searched bucket name, use ‘cat’ command to inspect the bucket. Copy and inspect in CyberChef the file. Start unpacking and remember to pipe the output whenever needed.
Objective 3a – Linux Primer – no clues were needed 🙂
Objective 3b – Point-of-Sale Password Recovery – clues give at a Discord were: download the package, no need to install the shop. Unpack the exe file, and poke around until you find app.asar and use 7zip to open Asar file.
Later today, 5-7pm GMT we will be focusing on following tasks:
all unfinished past tasks
Objective 4a – Unescape Tmux – no help needed
Objective 4b – Santavator operations – no help needed
Objective 5a – Speaker UNPrep – first clue: ‘strings door’ with some filters, more clues @Discord
Objective 5b – 5b: 33 Gkbps – no help needed
Objective 5c – Open the HID lock in the Workshop – no help needed
Objective 6a – Regex Toy Sorting – we will battle it together @Discord
Objective 6b – Splunk Challenge – clue: look for Bro.
So, as promised we are going to start SANS Holiday Hack Challenge Redo run by Counter Hack Team. We will start with the latest 2020 challenge . You will need a valid email to create user account, which is instant. You can start straight away on your own or watch a couple helpful videos.
The first video that I would like talk about, it’s Ed Skoudis 2020 Hack Challenge Intro. Video is a great overview of this year challenge.
Second video is aimed at Hack Challenge first timers, it’s walk through the login page and the starting interface.
For the last five years I was getting more and more anxious the closer it was till the end of the year. Why so? The answer is very simple – the SANS Hack Challenge (https://holidayhackchallenge.com/2020/index.html) run online by Counter Hack Team (https://www.counterhack.com/expert-pen-testers). I have learnt plenty and had an immeasurable amount of fun while solving hacking challenges. This winter I found myself helping others with their tasks by giving hints and I discovered that I have learnt even more. The best part was seeing others to grow and to learn how to beat the tasks.
Unfortunately, SANS hack challenge is only once a year and I didn’t always managed to find enough spare time to solve all the puzzles. Luckily, there is a way to fix that.
So, this year to celebrate 12th birthday of Tog, there will be a pleasant surprise. A walk through a past SANS Holiday Challenges. We will start on the 23rd of January, all info will be posted online. So, keep an eye on our website and reserve time between 5 pm and 7 pm on the day to join the discussion on a dedicated Discord channel https://discord.gg/322Kw4bkQK.
TOG turned eleven this year and in those eleven years we have gone from strength to strength. We currently find ourselves in our third space at 22 Blackpitts in the south city centre. It has been a great home to us for these past 5 years. Our lease expires shortly and although we will be renewing, we do not know if we will have a long term lease and the building might also end up for sale.
So we are beginning our search for a new long-term home which will become TOG 4.0. We would like to find a space between the canals if possible, and ideally in the city centre. In the mean time, we continue with our visitor activities (online due to Covid 19) and TOG members can still physically access and use the space. We continue to welcome new members. So keep in touch with us and if you know of any locations which which may be of interest to us, drop us a line. Closeness to public transport is a plus, given our diverse membership and visitor profile. We might also be interested in partnering or co-locating with other organisations. We will keep you informed of any developments.