Posts

Showing posts from January, 2020

SANS Holiday Hack Challenge 2019

Image
KringleCon 2 - Objective 12  12) Filter Out Poisoned Sources of Weather Data Difficulty: 🎄🎄🎄🎄 (4/5) Use the data supplied in the Zeek JSON logs to identify the IP addresses of attackers poisoning Santa's flight mapping software. Block the 100 offending sources of information to guide Santa's sleigh through the attack. Submit the Route ID ("RID") success value that you're given. For hints on achieving this objective, please visit the Sleigh Shop and talk with Wunorse Openslae. Wunorse Openslae Wunorse Openslae here, just looking at some Zeek logs. I'm pretty sure one of these connections is a malicious C2 channel... Do you think you could take a look? I hear a lot of C2 channels have very long connection times. Please use jq to find the longest connection in this data set. We have to kick out any and all grinchy activity! So this is the part we do the cranpi Terminal..., the terminal was made f...

SANS Holiday Hack Challenge 2019

Image
KringleCon 2 - Obj 0 to 5 0) Talk to Santa in the Quad This is Santa! (Who knew?!) This is Santa with an Umbrella in the Quad ( Talk to him ) Talk to the Santa with the Umbrella until he repeats himself, then your first objective should be done, and  4 more objectives should be added:  1) Find the Turtle Doves  2) Unredact Threatening Document  3) Windows Log Analysis: Evaluate Attack Outcome  4) Windows Log Analysis: Determine Attacker Technique  5) Network Log Analysis: Determine Compromised System 1) Find the Turtle Doves Your first mission is to find the Turtle Doves, they are in the Student Union, to the left side, next to the fireplace Fireplace Very Important Turtle Doves Just click on them and your first objective will be completed 2) Unredact Threatening Document As you exit the Student Union hall, go all the way to the left side, in the corner, behind a pine tree, there's a document, just click on it to...