Page 1 of 3 123 LastLast
Results 1 to 10 of 21

Thread: HaXx.Me #04 - Pentesting the Obscure

  1. #1
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    HaXx.Me #04 - Pentesting the Obscure

    Dear members and guests of InterN0T,


    The last three HaXx.Me #01 #02 and #03 wargames were a success and therefore
    it is time for HaXx.Me #04! We've given you time to recover from the last challenge
    which included strange DNS queries, Custom Web Apps, Custom vHost requests
    and much more! This time, we guarantee it will be even more mind blowing!

    Not only will the challenge contain Web Applications as per usual, but it will
    also include insanity on a high level in form of pentesting ways, some of you
    may never have encountered nor tried before.

    Of course you may have heard of it, but one thing is theory, another is real life.

    The target will be announced here in this thread, on twitter and IRC, while the complete
    objectives will only be released here. There are a few rules (common sense) which has
    to be followed as well, these are mentioned below.

    The challenge is "Capture The Flag" styled, as in completing the objective(s) first.


    Winners
    1st: VADiUM
    2nd: Hawkje - Badjashackers
    3rd: Xero with Team Fn0rd
    4th: s3my0n
    5th: Corelan Team

    Other participants who completed the contest:

    vndctv, sphyrath, flagitiouslogic, theologu, Saif, mohamed ramadan, 5M7X


    Documentation
    5M7X: http://vimeo.com/17421921 | Supplemental: http://vimeo.com/17473857
    mohamed ramadan: http://blip.tv/file/4461732
    sphyrath: http://intern0t.net/docs/sphyrath01.pdf
    The_UnKn0wn: http://intern0t.net/docs/theunkn0wn01.pdf
    InterN0T (LQ): http://intern0t.blip.tv/
    InterN0T (HQ): http://rapidshare.com/files/435700651/HaXx.Me-04-2.mp4


    Rules
    - It is forbidden to intentionally cause DoS conditions.
    - It is strictly forbidden to try and break out of the Xen instance.
    - Attacking other servers on the same host or network is strictly forbidden.
    - You may only attack the IP and domain announced here.
    - Avoid altering the target to deny other contest participants access.
    - You may attack any service hosted on the target.
    - You may use any tool necessary to hack the target as long as you don't break the rules above.
    - Avoid automated vulnerability scanners. They won't help you and it may cause the server to become slow.
    - You are allowed to use NMAP, otherwise you won't be able to do this challenge. (Don't use the -A flag / switch.)


    Hints
    - There's a lot more to it, than just Web Application Security.
    - Check out twitter from time to time, hints may be revealed occasionally.
    - Read blogs and threads on InterN0T about Web Application Security.
    - Having completed the last 3 challenges or at least knowing how, is a plus.


    Contact
    - In case the server is down, contact Hestas or Rorok and inform them about this.
    - You can also send a PM to me or use our Contact Us form.


    Timeline
    The challenge starts Friday the 26th November 2010 - 18:00 GMT+1 (12:00pm EST)
    The challenge ends roughly around Fridaythe 3rd December 2010.


    Submissions
    In order for us to see how you managed to "crack" the server, we'd like you
    to provide some brief documentation. The layout overall doesn't matter but
    One could look at the HSIYF documentation others made, to get an idea how
    such a thing could look like. Alternatively check out the previous documentations
    from the last challenges!


    Challenge
    The target server may be restored from a backup each ~24 hours.



    HaXx.Me #04 Target
    Target: [CLOSED]


    Primary Objectives:

    • Gain access to and read the contents of the "Winning-Key.txt" file in the root directory.

    Don't forget to have fun while you're doing this!

    If you fail, don't believe you're not good enough. Try Harder as the people
    from Offensive Security tend to say, or simply give up and wait for the full
    documentation which usually includes a video from InterN0T.



    Best regards,
    MaXe


  2. #2
    Join Date
    Jul 2010
    Location
    Wisconsin.
    Posts
    285
    Blog Entries
    1
    Reputation
    128
    Rep Power
    4

    Re: HaXx.Me #04 - Pentesting the Obscure

    Sounds like it's gonna be a great time
    The greatest trick the devil ever pulled was convincing the world that he didn't exist.
    To complete a successful attack, you must convince the target that YOU don't exist.

  3. #3
    Join Date
    Oct 2010
    Location
    Egypt
    Posts
    27
    Reputation
    16
    Rep Power
    4

    Re: HaXx.Me #04 - Pentesting the Obscure

    MaXe when will the target be announced

    we see the impossible and then exploit it

  4. #4
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10

    Re: HaXx.Me #04 - Pentesting the Obscure

    Quote Originally Posted by saif View Post
    MaXe when will the target be announced
    Sometime during this week, I'm using a lot of time planning, configuring and setting up the challenge at the moment.

    I should note that this will be the hardest challenge you may have ever seen. (of the HaXx.Me challenges)


  5. #5
    MaXe's Avatar
    MaXe is offline Founder of InterN0T
    Join Date
    Jun 2008
    Location
    Denmark
    Posts
    4,140
    Blog Entries
    41
    Reputation
    270
    Rep Power
    10
    Thread updated with more information. Good luck to anyone participating!

    HaXx.Me #04 has begun! Good luck to anyone participating!


  6. #6
    Join Date
    Mar 2010
    Posts
    16
    Reputation
    1
    Rep Power
    5

    Re: HaXx.Me #04 - Pentesting the Obscure

    Let see what you have done ! :D

  7. #7
    Join Date
    Oct 2010
    Posts
    8
    Reputation
    1
    Rep Power
    4

    Re: HaXx.Me #04 - Pentesting the Obscure

    LOL "Ask me a text record, the right way for: 127.0.0.1 PTR IN-ADDR.ARPA" :D

  8. #8
    Join Date
    Feb 2010
    Location
    Manila, Philippines
    Posts
    86
    Reputation
    33
    Rep Power
    5

    Re: HaXx.Me #04 - Pentesting the Obscure

    konichiwa intern0t! it's been a while :)
    Doubt whom you will, but never yourself.

  9. #9
    Join Date
    Mar 2010
    Posts
    16
    Reputation
    1
    Rep Power
    5

    Re: HaXx.Me #04 - Pentesting the Obscure

    i tried nslookup and i get nothing...

    LE: Do not say anything ! I want to find it myself !

  10. #10
    s3my0n's Avatar
    s3my0n is online now #!/usr/bin/env s3my0n
    Join Date
    Sep 2009
    Location
    /home/s3my0n/
    Posts
    669
    Blog Entries
    3
    Reputation
    398
    Rep Power
    9

    Re: HaXx.Me #04 - Pentesting the Obscure

    It was as they say - "A fun hack" ;D

    Thanks MaXe, best HaXx.Me yet.
    In view of such harmony in the cosmos which I, with my limited human mind, am able to recognise, there are yet people who say there is no God. But what makes me really angry is that they quote me for support of such views.
    Albert Einstein

Page 1 of 3 123 LastLast

LinkBacks (?)


Similar Threads

  1. NeoPwn - Mobile Pentesting
    By MaXe in forum Hacking Tools & Utilities
    Replies: 20
    Last Post: 27th February 2012, 13:39
  2. HaXx.Me #03 - Web App Sec for Pro's
    By MaXe in forum InterN0T Contests
    Replies: 4
    Last Post: 26th October 2010, 16:04
  3. HaXx.Me #02 how helped me
    By impelse in forum General Hacking Discussions
    Replies: 1
    Last Post: 8th October 2010, 15:03
  4. Offensive Security Pentesting Video (new release) 4/29/10
    By gruenfeld777 in forum Offensive Guides & Information
    Replies: 0
    Last Post: 29th April 2010, 08:15
  5. Is there good money in pentesting?
    By gruenfeld777 in forum General Hacking Discussions
    Replies: 2
    Last Post: 25th March 2010, 16:41

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
EvilZone py1337 SoldierX.com TheXero Get-Root HackTalk
PenTest Magazine

HatForce