capture the flag, cybersecurity education, hacking, owasp, web application security

#PwnItFridays @hackthebox_eu Staring Point Series: Redeemer Machine

Another day, another challenge.

I’m restarting the series #PwnItFriday where I hack machines from hackthebox and TryHackMe.

Without further ado, the machine I’m solving today is Redeemer.

Topics explored in this machine are connecting to a Redis server, vulnerability assessments, database, reconnaissance, and anonymous/guest access.

Click the video to learn how to solve this machine!

Like the content — support by Buying a Coffee

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 24 – The Year Of The Bandit Yeti #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

In our twenty-fourth challenge, we’re wrapping up the final details for Santa to safely deliver presents to the children.

The topics explored in this challenge are a survey of the Advent of Cyber event. Other rooms to explore to continue learning about cybersecurity, and finally, the last day to be eligible to receive prizes is December 28th.

Did the elves save Christmas? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 21 – Have Yourself A Merry Little Webcam #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

In our twenty first challenge, we’re tasked with determining if the web camera on our device has any vulnerabilities. The elves are confident there are no vulnerabilities, but we’ll check to see if there are any off-the-shelf exploits are available to exploit the device.

The topics explored in this challenge are learning what are IoT (Internet of Things), and their (potential security vulnerabilities). The different protocols surrounding IoT. Finally, understanding the publish/subscribe model that is used for IoT.

Can we help Santa find the weaknesses on the web server before the bad guys? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 23 – Mission ELFPossible: Abominable For A Day #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

In our twenty-third challenge, we’re tasked as Bad Yeti to get Santa’s Vault password and flags. The challenge grows in difficulty as more defense layers are added.

The topics explored in this challenge are in-depth defense tactics such as disrupting adversarial objectives by reviewing the three levels of defense. The first level focuses on perimeter security. The second level focuses on defense in layers with an emphasis on prevention. The third and final level builds upon level two but adds alerting and response capabilities.

Can we beat the game with the different defense layers in place? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 22 – Threats Are Failing All Around Me #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

In our twenty-second challenge, the elves want to improve Santa’s security posture after the recent attempts to disrupt Christmas.

The topics explored in this challenge are understanding an attack vector and the concept of an attack surface.

Can we help the elves update Santa’s servers before Christmas? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 9 – Dock The Halls #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

In our ninth challenge, we discover there’s a recent incident. Because of this, Santa wanted to set up a web application running on Docker as it’s supposed to be more secure. Our job is to show there are still weaknesses while using Docker.

The topics explored in this challenge are Metasploit, which can be used to compromise systems. We also learned network pivoting and post-exploitation.

Can we help Santa find the weaknesses on the web server before the bad guys? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 19 – Wiggles Go Brr #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

We had a hardware implant in Santa’s workshop in our nineteenth challenge. We have to analyze the implant to understand how it works.

The topics explored in this challenge are hardware communication protocols such as USART, SPI, and I2C. Along with how to analyze these protocols.

Can we help Santa determine how the hardware implant works? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 20 – Binwalkin’ Around The Christmas Tree #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

In our twentieth challenge, we’re learning more about the device found in Santa’s workshop. In this challenge, we learned the Device ID, and now we have to reverse engineer the device to determine the firmware and endpoints.

The topics explored in this challenge are firmware reverse engineering, extracting code from firmware, and modifying and rebuilding firmware.

Can we reverse-engineer the device to help Santa? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 16 – SQLi’s The King, The Carolers Sing #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

In our sixteenth challenge, Elf McSkidy asked Elf Exploit and Elf Admin to assist in clearing the application. When presented with the app’s code, both elves looked a bit shocked, as none of them knew how to make any sense of it, let alone fix it.

The topics explored in this challenge are Structured Query Language (SQL) and the vulnerability – SQL injection. SQL Injection happens when a website creates a dynamic query using user input (without being sanitized/validated). The final topic was ways to mitigate this vulnerability, such as parameterized queries.

Can we help Elf Exploit and Elf Admin secure the website? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007

capture the flag, cybersecurity education, hacking

@RealTryHackMe #AdventOfCyber Series: Challenge 18 – Lumberjack Lenny Learns New Rules #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series, the Advent of Cyber, hosted by TryHackMe. This is the fourth year of the Advent of Cyber, where a challenge is released every day leading to Christmas. There will be 25 challenges; we’re McSkidy, an elf trying to save Christmas.

In our eighteenth challenge, we discovered The Best Festival Company Infrastructure has been compromised! Through logs, we determined that Bandit Yeti was the likely culprit. Our job is to experiment and learn threat detection rules to determine the root cause of how Bandit Yeti compromised the system.

The topics explored in this challenge are threat detection, which analyzes abnormal activity, such as malicious signs of compromise on a network. A tool that can be used for threat detection is Sigma. Sigma allows us to create rules to look for malicious activity, such as new user accounts or editing scheduled tasks.

Can we use threat detection tools to find the root cause of Santa’s compromise? Find out below!

If you enjoy my content, buy me a coffee. Link –> http://buymeacoffee.com/thefluffy007