On the forensic-task CTF got a file of 2 MB without extension. file returned the succinct "data". Binwalk was silent. I open the hex editor - the first eight bytes are scored by zeros. Someone rubbed them deliberately. The definition of file type by magictes manually took three minutes: line...
Web-task on CTF: the form of downloading SVG-avatar, from endpoints upload - only and the user profile. Half of the participants pick XSS in SVG rendering, try SSTI, torment CSPs — and the first solver comes through the XXE injection into a SVG parser with a chain to SSRF on the internal API...
The specialists of Zscaler discovered a new backdoor C2Looper, which intruders are likely to use before attacks with ransomware. The malicious program allows you to discreetly fix yourself in the network, collect information about computers, execute commands and download additional malicious...
Victims of ransomware faced a new scheme: soon after the attack, they write an unknown company that already knows about the stolen data and offers for money to remove them from criminals. GuidePoint Security experts believe that a participant in several criminal operations is hiding behind the...
The developers attacked through fake packages at once in two popular repositories. The attackers placed 16 malicious libraries in RubyGems and another 37 in npm, picking up names with typos for known dependencies. Installation of bait on Windows launched StubMaker, a data snatch that collected...
Ads in Firefox for iOS can now disappear before the page is loaded. Mozilla has started to gradually add a built-in blocker to the browser, so users won't need a separate app or extension. The experimental function has not yet appeared at all and by default is disabled.
After activation...
In the darknet, the declared 3.64 million records from the corporate directories of Microsoft Azure and Entra were put on sale. The seller, under the pseudonym TheHatman, attributes the bases to nine major companies, including McDonald’s, Vodafone, Tata Consultancy Services and HCL Technologies...
People have long come up with stories about desires filled too literally. King Midas gained the ability to turn everything he touched into gold, but with innumerable wealth lost his normal life. In the story “Monkey’s noodle” desires also come true, but the result each time turns out to be not...
Business logic SQL injections and location in MITRE ATT&CK
Why would an attacker bypass WHERE through a SQL injection? The ultimate goal is simple – to get to data that the application does not access: password hashes, personal data, and in CTF – a flag. In MITRE ATT&CK SQL injection in the...
Preparing the Environment for CTF Shell Scripts
Before copying scripts – two checks that save from the loss of time already in the competition.
The first is to make sure that bash is used, not dash or sh. In Debian and Ubuntu /bin/sh refers to the dash where /dev/tcp There is no and half of...
On the Dojo CTF challenge #36 from YesWeHack, members were planted a web form with a ping – a classic entry point for an OS command injection. The filter on the application side missed payload only if it did not have a single Latin letter: regular [a-zA-Z_*^@%+=:,./-] sent the input to the...
For the last two years, I've been collecting pcap assignments for CTFs and on each parse, I observe one picture: participants open the file and leaf the packets from top to bottom. On a dump of 50 thousand packages, it takes half an hour and gives zero result. And after all Statistics → Protocol...
The new computer could be infected before the first entry of the employee and the installation of the antivirus. The spy group GOFFEE has built backdoors into the corporate ISO-images of Windows, and in the internal storage of the Russian company replaced the executable files 7-Zip and Git. A...
Chinese chat-bots with artificial intelligence are noticeably worse than Western competitors recognize false claims in favor of China, and on sensitive questions for Beijing often prefer not to answer at all. This conclusion came from the NewsGuard service, checking seven popular Chinese...
The HoneyMyte (Mustang Panda) group has significantly increased the CoolClient backdoor. The new version has received a driver for the Windows kernel, which helps to hide malicious process, files, registry records and network activity. The updated CoolClient has already been applied against...
On the last CyberDefenders-shuttle on the network networks of 200 participants only 38 found the second flag. It was hidden in the ICMP packet data field — by-bited by echo-requests between the two hosts. The other 162 people stopped after strings evidence.pcap | grep flag and decided that the...
Jeopardy CTF is the format from which everyone starts
Jeopardy (or Task-Based) is the most common format of the flag of the competition. The name was pulled from the American TV quiz: participants are given a board with tasks broken down by categories and levels of difficulty. The task is to...