Haven't written in a while... been busy with life. I had an awesome opportunity. I was invited to the NetWars Tournament of Champions in Berlin. Problem was that that kind of trip was a bit expensive for me. Mostly because of the flight. Somehow I was lucky and it worked out that they needed a facilitator. So, I did SANS training at a discounted price, and came to Berlin.
Being a facilitator for SANS EMEA is a bit more involved than the US one. We had to run network cables for our rooms, set up the books and supplies in each room on the desks in a neat orderly fashion and put the bags on the seat backs, make sure that our instructors had a speaker set up to play music, a speaker set up for his wireless mic, a projector or a screen, we had to set up the cabling/network the rooms if we had a wired setup, and we had to set up the cabling/network for NetWars. (I was glad that this seemed to be ok. Few hiccups here and there, but better than expected. I was so worried something would go wrong.)
I'm so glad that in the US, SANS has the AV team to help with setting up stuff. I appreciate them; even more now. Thanks for all you do, you unsung heroes.
I took SANS SEC617: Wireless Pen Testing and Ethical Hacking - have I ever done this. Nope. Do I know much about wireless tech? Nope.
The above isn't exactly what I intended to write about today, though. Kind of worried about writing this - what people would think. But I think others feel like this, so it might be helpful.
TLDR: When you don't know everything, which pretty much includes
everyone, do your best to help in the ways that you can. That's good
enough. :)
I'm not the smartest person in the room. Not by a long shot. Sometimes I wonder why I'm here. As in why am I in information security? Do I deserve to be here? People always tell me, "It's imposter syndrome." Saying it's imposter syndrome doesn't help take away the feeling. Also, what if I'm right? What if I'm not an imposter? What if I really don't know all that much? I know enough to know that I need to learn more. I don't consider myself "expert" in anything. People act like it's bad for me to doubt myself. Is it really bad to feel this way considering it gives me a drive to learn more?
I was feeling overwhelmed this week because this class covers something I've never done before. I also missed some of class because of my Facilitator duties. (This happens from time to time, but that's why they give us OnDemand.) So I was feeling a little down all week - very much doubting myself. (Also, I know that this sounds stupid, but I've gotten cold sores for
as long as I can remember, so I was feeling down by that as well. I'm
so embarrassed by them. Sure, I can't help it that they come on, but
they bother me. I try my best to keep my hands away from my face, and
to keep my hands clean because I wouldn't be able to deal with it if I
accidentally infect someone. There are antivirals and such, but I find
that they don't help with mine. I have no idea how to cover them either - I don't wear makeup or anything. I know - stupid thing to be worried about, but that's me...)
Day 6 Challenge was today. I'm choked big time. Thankfully I had some really talented members on my team that picked up the slack. I recovered my brain enough sometime in the day to answer a couple of flags. Even when I was choking, I didn't give up. I kept trying. Maybe I couldn't help in the way that I wanted, but I found information in our books to help solve some of the puzzles and shared them with my team. Sure, maybe they already knew that, but maybe not. (We weren't talkative - if I have any advice for teams - talk it out.) I tried to be helpful where I could.
The point I actually want to make. It's ok not to be the smartest person in the room. I can't quit or stop trying just because someone is smarter than me. (Well, I can, but it wouldn't exactly be helpful to me or others.) I have an example to set for my children. How do I want them to react when they feel this way? I want to be a good example for them. Here's what I'm telling myself, so my children and maybe others can learn this from me. There may always be people that are smarter than you are. That's ok. We all have strengths and weaknesses. You're stronger when you help lift other people up, and you're not
afraid to learn from ANYONE. Yes, literally anyone. That means not
being afraid to ask for help when it's needed. So, I'm not awesome at wireless pen testing, YET, but I can learn from those who are and get better, in exchange, maybe they could learn something from me, or maybe they just simply feel better about themselves for helping someone else out. And I can't even say that I'm not good wireless pen testing because I've never actually tried until now. Who says I can't learn it? A one-week course isn't going to teach me all the ends/outs of wireless technology. Don't give up before you've had the chance to put in a good effort. (I'm amazed that I did actually learn stuff in class this week. It was
the implementation of those things that I was having trouble with.
But, I learned from that failure - probably more than if I would've been successful. This is all that matters. If you get into info sec, get used to failures - exploits - and WEP cracking - lolz - apparently - don't always work.)
Even if I never get awesome at wireless pen testing, is that ok? Yes, because I'm good at other things; like inspiring and encouraging others. Maybe when they're feeling like they can't go on, one inspiring message keeps them going. Even though I talk a lot about me; it's not about me. There are teams for a reason. Where someone is weak, others can pick up the slack. Even if someone is strong, even they don't know everything. Everyone's ideas give the inspiration needed to solve the puzzles.
I know that this message seems a bit simple, but sometimes that's what people need.
Sunday, July 28, 2019
Saturday, February 2, 2019
Tribe of Hackers
Saw a tweet by Marcus J. Carey about a book called Tribe of Hackers that was co-written with Jennifer Jin. Adding a link to their blog post to get the free pdf. I’m also purchasing the book as well.
I love that they’re releasing the book for free for those who can’t afford it.
I haven’t told my whole story, but I had it tough growing up. I originally didn’t even consider a career in IT because I felt I wasn’t intelligent enough, but also because I couldn’t afford it.
It’s awesome to see that someone is not only willing to spend their time mentoring others, but they are also giving this book for free to those who need it the most. Please purchase the book if you can, and spread the word about it. Thanks to Marcus Carey and Jennifer Jin for mentoring others and giving them this gift.
Without further ado, here’s the link: https://www.threatcare.com/tribe-of-hackers-free-pdf/
I love that they’re releasing the book for free for those who can’t afford it.
I haven’t told my whole story, but I had it tough growing up. I originally didn’t even consider a career in IT because I felt I wasn’t intelligent enough, but also because I couldn’t afford it.
It’s awesome to see that someone is not only willing to spend their time mentoring others, but they are also giving this book for free to those who need it the most. Please purchase the book if you can, and spread the word about it. Thanks to Marcus Carey and Jennifer Jin for mentoring others and giving them this gift.
Without further ado, here’s the link: https://www.threatcare.com/tribe-of-hackers-free-pdf/
Tuesday, January 15, 2019
SANS Holiday Hack 2018 - Storyline Questions and Answers
As you walk through the gates, a familiar red-suited holiday figure warmly welcomes all of his special visitors to KringleCon.
Welcome, my friends! Welcome to my castle! Would you come forward please?
Welcome. It’s nice to have you here! I’m so glad you could come. This is going to be such an exciting day!
I hope you enjoy it. I think you will.
Today is the start of KringleCon, our new conference for cyber security practitioners and hackers around the world.
KringleCon is designed to share tips and tricks to help leverage our skills to make the world a better, safer place.
Remember to look around, enjoy some talks by world-class speakers, and mingle with our other guests.
And, if you are interested in the background of this con, please check out Ed Skoudis’ talk called START HERE.
Delighted to meet you. Overjoyed! Enraptured! Entranced! Are we ready? Yes! In we go!
Question 1:
What phrase is revealed when you answer all of the KringleCon Holiday Hack History questions? For hints on achieving this objective, please visit Bushy Evergreen and help him with the Essential Editor Skills Cranberry Pi terminal challenge.
Answer: Happy Trails
Question 2:
Who submitted (First Last) the rejected talk titled Data Loss for Rainbow Teams: A Path in the Darkness? Please analyze the CFP site to find out. For hints on achieving this objective, please visit Minty Candycane and help her with the The Name Game Cranberry Pi terminal challenge.
Answer: John McClane
Question 3:
The KringleCon Speaker Unpreparedness room is a place for frantic speakers to furiously complete their presentations. The room is protected by a door passcode. Upon entering the correct passcode, what message is presented to the speaker? For hints on achieving this objective, please visit Tangle Coalbox and help him with the Lethal ForensicELFication Cranberry Pi terminal challenge.
Answer: Welcome unprepared speaker!
Suddenly, all elves in the castle start looking very nervous. You can overhear some of them talking with worry in their voices.
The toy soldiers, who were always gruff, now seem especially determined as they lock all the exterior entrances to the building and barricade all the doors. No one can get out! And the toy soldiers' grunts take on an increasingly sinister tone.
Grunt!
Question 4:
Retrieve the encrypted ZIP file from the North Pole Git repository. What is the password to open this file? For hints on achieving this objective, please visit Wunorse Openslae and help him with Stall Mucking Report Cranberry Pi terminal challenge.
Answer: Yippee-ki-yay
In the main lobby on the bottom floor of Santa's castle, Hans calls everyone around to deliver a speech.
Ladies and Gentlemen…
Ladies and Gentlemen…
Due to the North Pole’s legacy of providing coal as presents around the globe they are about to be taught a lesson in the real use of POWER.
You will be witnesses.
Now, Santa… that's a nice suit… John Philips, North Pole. I have two myself. Rumor has it Alabaster buys his there.
I have comrades in arms around the world who are languishing in prison.
The Elvin State Department enjoys rattling its saber for its own ends. Now it can rattle it for ME.
The following people are to be released from their captors.
In the Dungeon for Errant Reindeer, the seven members of the New Arietes Front.
In Whoville Prison, the imprisoned leader of ATNAS Corporation, Miss Cindy Lou Who.
In the Land of Oz, Glinda the Good Witch.
Question 5:
Using the data set contained in this SANS Slingshot Linux image, find a reliable path from a Kerberoastable user to the Domain Admins group. What’s the user’s logon name (in username@domain.tld format)? Remember to avoid RDP as a control path as it depends on separate local privilege escalation flaws. For hints on achieving this objective, please visit Holly Evergreen and help her with the CURLing Master Cranberry Pi terminal challenge.
Answer: LDUBEJ00320@AD.KRINGLECASTLE.COM
The toy soldiers continue behaving very rudely, grunting orders to the guests and to each other in vaguely Germanic phrases.
Links.
Nein! Nein! Nein!
No one is coming to help you.
Get the over here!
Schnell!
Suddenly, one of the toy soldiers appears wearing a grey sweatshirt that has written on it in red pen, "NOW I HAVE A ZERO-DAY. HO-HO-HO."
A rumor spreads among the elves that Alabaster has lost his badge. Several elves say, "What do you think someone could do with that?”
Question 6:
Bypass the authentication mechanism associated with the room near Pepper Minstix. A sample employee badge is available. What is the access control number revealed by the door authentication panel? For hints on achieving this objective, please visit Pepper Minstix and help her with the Yule Log Analysis Cranberry Pi terminal challenge.
Answer: 19880715
Hans has started monologuing again.
So, you’ve figured out my plan – it’s not about freeing those prisoners.
The toy soldiers and I are here to steal the contents of Santa’s vault!
You think that after all my posturing, all my little speeches, that I’m nothing but a common thief.
But, I tell you -- I am an exceptional thief.
And since I've moved up to kidnapping all of you, you should be more polite!
Question 7:
Santa uses an Elf Resources website to look for talented information security professionals. Gain access to the website and fetch the document C:\candidate_evaluation.docx. Which terrorist organization is secretly supported by the job applicant whose name begins with "K"? For hints on achieving this objective, please visit Sparkle Redberry and help her with the Dev Ops Fail Cranberry Pi terminal challenge.
Answer: Fancy Beaver
Great work! You have blocked access to Santa's treasure... for now.
And then suddenly, Hans slips and falls into a snowbank. His nefarious plan thwarted, he's now just cold and wet.
Question 8:
Santa has introduced a web-based packet capture and analysis tool to support the elves and their information security work. Using the system, access and decrypt HTTP/2 network activity. What is the name of the song described in the document sent from Holly Evergreen to Alabaster Snowball? For hints on achieving this objective, please visit SugarPlum Mary and help her with the Python Escape from LA Cranberry Pi terminal challenge.
Answer: Mary Had a Little Lamb
Question 9:
Alabaster Snowball is in dire need of your help. Santa's file server has been hit with malware. Help Alabaster Snowball deal with the malware on Santa's server by completing several tasks. For hints on achieving this objective, please visit Shinny Upatree and help him with the Sleigh Bell Lottery Cranberry Pi terminal challenge. Assist Alabaster Snowball by accessing the Snort terminal in Kringle Castle. What is the success message displayed by the Snort terminal?
Answer: Snort is alerting on all ransomware and only the ransomware!
Thank you so much! Snort IDS is alerting on each new ransomware infection in our network.
Hey, you're pretty good at this security stuff. Could you help me further with what I suspect is a malicious Word document?
All the elves were emailed a cookie recipe right before all the infections. Take this document with a password of elves and find the domain it communicates with.
Question 10:
After completing the prior question, Alabaster gives you a document he suspects downloads the malware. What is the domain name the malware in the document downloads from?
Answer: erohetfanu.com
Erohetfanu.com, I wonder what that means?
Unfortunately, Snort alerts show multiple domains, so blocking that one won't be effective.
I remember another ransomware in recent history had a killswitch domain that, when registered, would prevent any further infections.
Perhaps there is a mechanism like that in this ransomware? Do some more analysis and see if you can find a fatal flaw and activate it!
Question 11:
Analyze the full malware source code to find a kill-switch and activate it at the North Pole's domain registrar HoHoHo Daddy.
What is the full sentence text that appears on the domain registration success message (bottom sentence)?
Answer: Successfully registered yippeekiyaa.aaay!
Yippee-Ki-Yay! Now, I have a ma... kill-switch!
Now that we don't have to worry about new infections, I could sure use your L337 security skills for one last thing.
As I mentioned, I made the mistake of analyzing the malware on my host computer and the ransomware encrypted my password database.
Take this zip with a memory dump and my encrypted password database, and see if you can recover my passwords.
One of the passwords will unlock our access to the vault so we can get in before the hackers.
Question 12:
After activating the kill-switch domain in the last question, Alabaster gives you a zip file with a memory dump and encrypted password database. Use these files to decrypt Alabaster's password database. What is the password entered in the database for the Vault entry?
Answer: ED#ED#EED#EF#G#F#G#ABA#BA#B
You have some serious skills, of that I have no doubt.
There is just one more task I need you to help with.
There is a door which leads to Santa's vault. To unlock the door, you need to play a melody.
Question 13:
Use what you have learned from previous challenges to open the door to Santa's vault. What message do you get when you unlock the door?
Answer: You have unlocked Santa's vault!
Having unlocked the musical door, you enter Santa's vault.
I'm seriously impressed by your security skills!
How could I forget that I used Rachmaninoff as my musical password?
Of course I transposed it it before I entered it into my database for extra security.
Alabaster steps aside, revealing two familiar, smiling faces.
It’s a pleasure to see you again.
Congratulations.
You DID IT! You completed the hardest challenge. You see, Hans and the soldiers work for ME. I had to test you. And you passed the test!
You WON! Won what, you ask? Well, the jackpot, my dear! The grand and glorious jackpot!
You see, I finally found you!
I came up with the idea of KringleCon to find someone like you who could help me defend the North Pole against even the craftiest attackers.
That’s why we had so many different challenges this year.
We needed to find someone with skills all across the spectrum.
I asked my friend Hans to play the role of the bad guy to see if you could solve all those challenges and thwart the plot we devised.
And you did!
Oh, and those brutish toy soldiers? They are really just some of my elves in disguise.
See what happens when they take off those hats?
Santa continues:
Based on your victory… next year, I’m going to ask for your help in defending my whole operation from evil bad guys.
And welcome to my vault room. Where's my treasure? Well, my treasure is Christmas joy and good will.
You did such a GREAT job! And remember what happened to the people who suddenly got everything they ever wanted?
They lived happily ever after.
Question 14:
Who was the mastermind behind the whole KringleCon plan?
If you would like to submit a final report, please do so by emailing it to: SANSHolidayHackChallenge@counterhack.com
Answer: Santa
Congratulations on solving the SANS Holiday Hack Challenge 2018!
Welcome, my friends! Welcome to my castle! Would you come forward please?
Welcome. It’s nice to have you here! I’m so glad you could come. This is going to be such an exciting day!
I hope you enjoy it. I think you will.
Today is the start of KringleCon, our new conference for cyber security practitioners and hackers around the world.
KringleCon is designed to share tips and tricks to help leverage our skills to make the world a better, safer place.
Remember to look around, enjoy some talks by world-class speakers, and mingle with our other guests.
And, if you are interested in the background of this con, please check out Ed Skoudis’ talk called START HERE.
Delighted to meet you. Overjoyed! Enraptured! Entranced! Are we ready? Yes! In we go!
Question 1:
What phrase is revealed when you answer all of the KringleCon Holiday Hack History questions? For hints on achieving this objective, please visit Bushy Evergreen and help him with the Essential Editor Skills Cranberry Pi terminal challenge.
Answer: Happy Trails
Question 2:
Who submitted (First Last) the rejected talk titled Data Loss for Rainbow Teams: A Path in the Darkness? Please analyze the CFP site to find out. For hints on achieving this objective, please visit Minty Candycane and help her with the The Name Game Cranberry Pi terminal challenge.
Answer: John McClane
Question 3:
The KringleCon Speaker Unpreparedness room is a place for frantic speakers to furiously complete their presentations. The room is protected by a door passcode. Upon entering the correct passcode, what message is presented to the speaker? For hints on achieving this objective, please visit Tangle Coalbox and help him with the Lethal ForensicELFication Cranberry Pi terminal challenge.
Answer: Welcome unprepared speaker!
Suddenly, all elves in the castle start looking very nervous. You can overhear some of them talking with worry in their voices.
The toy soldiers, who were always gruff, now seem especially determined as they lock all the exterior entrances to the building and barricade all the doors. No one can get out! And the toy soldiers' grunts take on an increasingly sinister tone.
Grunt!
Question 4:
Retrieve the encrypted ZIP file from the North Pole Git repository. What is the password to open this file? For hints on achieving this objective, please visit Wunorse Openslae and help him with Stall Mucking Report Cranberry Pi terminal challenge.
Answer: Yippee-ki-yay
In the main lobby on the bottom floor of Santa's castle, Hans calls everyone around to deliver a speech.
Ladies and Gentlemen…
Ladies and Gentlemen…
Due to the North Pole’s legacy of providing coal as presents around the globe they are about to be taught a lesson in the real use of POWER.
You will be witnesses.
Now, Santa… that's a nice suit… John Philips, North Pole. I have two myself. Rumor has it Alabaster buys his there.
I have comrades in arms around the world who are languishing in prison.
The Elvin State Department enjoys rattling its saber for its own ends. Now it can rattle it for ME.
The following people are to be released from their captors.
In the Dungeon for Errant Reindeer, the seven members of the New Arietes Front.
In Whoville Prison, the imprisoned leader of ATNAS Corporation, Miss Cindy Lou Who.
In the Land of Oz, Glinda the Good Witch.
Question 5:
Using the data set contained in this SANS Slingshot Linux image, find a reliable path from a Kerberoastable user to the Domain Admins group. What’s the user’s logon name (in username@domain.tld format)? Remember to avoid RDP as a control path as it depends on separate local privilege escalation flaws. For hints on achieving this objective, please visit Holly Evergreen and help her with the CURLing Master Cranberry Pi terminal challenge.
Answer: LDUBEJ00320@AD.KRINGLECASTLE.COM
The toy soldiers continue behaving very rudely, grunting orders to the guests and to each other in vaguely Germanic phrases.
Links.
Nein! Nein! Nein!
No one is coming to help you.
Get the over here!
Schnell!
Suddenly, one of the toy soldiers appears wearing a grey sweatshirt that has written on it in red pen, "NOW I HAVE A ZERO-DAY. HO-HO-HO."
A rumor spreads among the elves that Alabaster has lost his badge. Several elves say, "What do you think someone could do with that?”
Question 6:
Bypass the authentication mechanism associated with the room near Pepper Minstix. A sample employee badge is available. What is the access control number revealed by the door authentication panel? For hints on achieving this objective, please visit Pepper Minstix and help her with the Yule Log Analysis Cranberry Pi terminal challenge.
Answer: 19880715
Hans has started monologuing again.
So, you’ve figured out my plan – it’s not about freeing those prisoners.
The toy soldiers and I are here to steal the contents of Santa’s vault!
You think that after all my posturing, all my little speeches, that I’m nothing but a common thief.
But, I tell you -- I am an exceptional thief.
And since I've moved up to kidnapping all of you, you should be more polite!
Question 7:
Santa uses an Elf Resources website to look for talented information security professionals. Gain access to the website and fetch the document C:\candidate_evaluation.docx. Which terrorist organization is secretly supported by the job applicant whose name begins with "K"? For hints on achieving this objective, please visit Sparkle Redberry and help her with the Dev Ops Fail Cranberry Pi terminal challenge.
Answer: Fancy Beaver
Great work! You have blocked access to Santa's treasure... for now.
And then suddenly, Hans slips and falls into a snowbank. His nefarious plan thwarted, he's now just cold and wet.
Question 8:
Santa has introduced a web-based packet capture and analysis tool to support the elves and their information security work. Using the system, access and decrypt HTTP/2 network activity. What is the name of the song described in the document sent from Holly Evergreen to Alabaster Snowball? For hints on achieving this objective, please visit SugarPlum Mary and help her with the Python Escape from LA Cranberry Pi terminal challenge.
Answer: Mary Had a Little Lamb
Question 9:
Alabaster Snowball is in dire need of your help. Santa's file server has been hit with malware. Help Alabaster Snowball deal with the malware on Santa's server by completing several tasks. For hints on achieving this objective, please visit Shinny Upatree and help him with the Sleigh Bell Lottery Cranberry Pi terminal challenge. Assist Alabaster Snowball by accessing the Snort terminal in Kringle Castle. What is the success message displayed by the Snort terminal?
Answer: Snort is alerting on all ransomware and only the ransomware!
Thank you so much! Snort IDS is alerting on each new ransomware infection in our network.
Hey, you're pretty good at this security stuff. Could you help me further with what I suspect is a malicious Word document?
All the elves were emailed a cookie recipe right before all the infections. Take this document with a password of elves and find the domain it communicates with.
Question 10:
After completing the prior question, Alabaster gives you a document he suspects downloads the malware. What is the domain name the malware in the document downloads from?
Answer: erohetfanu.com
Erohetfanu.com, I wonder what that means?
Unfortunately, Snort alerts show multiple domains, so blocking that one won't be effective.
I remember another ransomware in recent history had a killswitch domain that, when registered, would prevent any further infections.
Perhaps there is a mechanism like that in this ransomware? Do some more analysis and see if you can find a fatal flaw and activate it!
Question 11:
Analyze the full malware source code to find a kill-switch and activate it at the North Pole's domain registrar HoHoHo Daddy.
What is the full sentence text that appears on the domain registration success message (bottom sentence)?
Answer: Successfully registered yippeekiyaa.aaay!
Yippee-Ki-Yay! Now, I have a ma... kill-switch!
Now that we don't have to worry about new infections, I could sure use your L337 security skills for one last thing.
As I mentioned, I made the mistake of analyzing the malware on my host computer and the ransomware encrypted my password database.
Take this zip with a memory dump and my encrypted password database, and see if you can recover my passwords.
One of the passwords will unlock our access to the vault so we can get in before the hackers.
Question 12:
After activating the kill-switch domain in the last question, Alabaster gives you a zip file with a memory dump and encrypted password database. Use these files to decrypt Alabaster's password database. What is the password entered in the database for the Vault entry?
Answer: ED#ED#EED#EF#G#F#G#ABA#BA#B
You have some serious skills, of that I have no doubt.
There is just one more task I need you to help with.
There is a door which leads to Santa's vault. To unlock the door, you need to play a melody.
Question 13:
Use what you have learned from previous challenges to open the door to Santa's vault. What message do you get when you unlock the door?
Answer: You have unlocked Santa's vault!
Having unlocked the musical door, you enter Santa's vault.
I'm seriously impressed by your security skills!
How could I forget that I used Rachmaninoff as my musical password?
Of course I transposed it it before I entered it into my database for extra security.
Alabaster steps aside, revealing two familiar, smiling faces.
It’s a pleasure to see you again.
Congratulations.
You DID IT! You completed the hardest challenge. You see, Hans and the soldiers work for ME. I had to test you. And you passed the test!
You WON! Won what, you ask? Well, the jackpot, my dear! The grand and glorious jackpot!
You see, I finally found you!
I came up with the idea of KringleCon to find someone like you who could help me defend the North Pole against even the craftiest attackers.
That’s why we had so many different challenges this year.
We needed to find someone with skills all across the spectrum.
I asked my friend Hans to play the role of the bad guy to see if you could solve all those challenges and thwart the plot we devised.
And you did!
Oh, and those brutish toy soldiers? They are really just some of my elves in disguise.
See what happens when they take off those hats?
Santa continues:
Based on your victory… next year, I’m going to ask for your help in defending my whole operation from evil bad guys.
And welcome to my vault room. Where's my treasure? Well, my treasure is Christmas joy and good will.
You did such a GREAT job! And remember what happened to the people who suddenly got everything they ever wanted?
They lived happily ever after.
Question 14:
Who was the mastermind behind the whole KringleCon plan?
If you would like to submit a final report, please do so by emailing it to: SANSHolidayHackChallenge@counterhack.com
Answer: Santa
Congratulations on solving the SANS Holiday Hack Challenge 2018!
Friday, October 26, 2018
First Talk @ Wild West Hackin' Fest
I just gave my first talk at Wild West Hackin' Fest. Thanks for letting me present. :)
My spouse pestered me to submit a paper. So I submitted a half thought out idea of telling how a stay-at-home-mom ended up in info sec. I never expected in a million years that my topic would be chosen. I found out in June. I wanted to cancel, but before I could, my spouse took to Twitter and told everyone that I'd been accepted. So, I felt like I had to do this talk. I was scared, though, so I avoided writing anything like a plague. I had an idea of what I wanted to say - a direction I wanted to go in. I think that I failed in that respect. I told part of the story. I didn't say everything that I wanted to say.
If the talk belongs to me- not sure of the etiquette surrounding talks considering this was my first talk ever. I might record it as it's meant to be - when I'm not so nervous. I won't be on camera - it would just be my voice, and maybe slides. I requested that they not record it - they kindly obliged.
I'm slightly disappointed in myself, but also feel a little accomplished because I was brave enough to speak in front of people. I never thought I had it in me. I used to sing in front of crowds, but that's different because you're singing someone else's story - you're not expressing your own ideas. You also get swept away in the music - for me - it's like the room drops away and I'm just left with the music. Speaking on the other hand terrifies me. Weird, I know.
I see some women on Twitter noting why they are afraid to give talks - they're afraid that they won't have anything to say. To them - you probably have something much more important to talk about than being a mom who becomes an info sec pro. I talked about my kids during the talk for heaven's sake. Your journeys, experience, thoughts help people more than you realize. I've seen some of the incredible things that these young women have been up to, and don't understand why they can't see how awesome they are. My suggestion is - give it a shot - you might surprise yourself.
The people here at Wild West Hackin' Fest were so kind to me when the talk was over. They told me I did well - not sure I actually believe that they were sincere, but I didn't hear anything negative. Not saying no one said anything negative, but if they did, I didn't hear it. Submit your papers - be heard. Inspire other people.
My spouse pestered me to submit a paper. So I submitted a half thought out idea of telling how a stay-at-home-mom ended up in info sec. I never expected in a million years that my topic would be chosen. I found out in June. I wanted to cancel, but before I could, my spouse took to Twitter and told everyone that I'd been accepted. So, I felt like I had to do this talk. I was scared, though, so I avoided writing anything like a plague. I had an idea of what I wanted to say - a direction I wanted to go in. I think that I failed in that respect. I told part of the story. I didn't say everything that I wanted to say.
If the talk belongs to me- not sure of the etiquette surrounding talks considering this was my first talk ever. I might record it as it's meant to be - when I'm not so nervous. I won't be on camera - it would just be my voice, and maybe slides. I requested that they not record it - they kindly obliged.
I'm slightly disappointed in myself, but also feel a little accomplished because I was brave enough to speak in front of people. I never thought I had it in me. I used to sing in front of crowds, but that's different because you're singing someone else's story - you're not expressing your own ideas. You also get swept away in the music - for me - it's like the room drops away and I'm just left with the music. Speaking on the other hand terrifies me. Weird, I know.
I see some women on Twitter noting why they are afraid to give talks - they're afraid that they won't have anything to say. To them - you probably have something much more important to talk about than being a mom who becomes an info sec pro. I talked about my kids during the talk for heaven's sake. Your journeys, experience, thoughts help people more than you realize. I've seen some of the incredible things that these young women have been up to, and don't understand why they can't see how awesome they are. My suggestion is - give it a shot - you might surprise yourself.
The people here at Wild West Hackin' Fest were so kind to me when the talk was over. They told me I did well - not sure I actually believe that they were sincere, but I didn't hear anything negative. Not saying no one said anything negative, but if they did, I didn't hear it. Submit your papers - be heard. Inspire other people.
Sunday, July 1, 2018
SANS SEC560
Went to training this past week. Took SANS SEC560.
Choose the hotel you stay at wisely. I didn't sleep very well all week. There's always the chance of not sleeping well, but in this case, it was worse than usual. I can't fault the hotel; the beds were comfortable, the rooms were clean, etc. There was just so much noise around, the whole night. I did not stay in the SANS venue this time.
The class itself was great. The instructor was entertaining. He went a little fast, but he had a lot of material to cover. As usual, I was trying to take notes while he spoke. I'm glad I have On-Demand so I can listen to the lecture again from someone else's perspective and pause it when I feel the instructor is going too fast.
Feel like I learned a bit this week. Most of the learning was from doing dumb things.
There is a ctf in it. I can't give away exact answers. Here's a few tips:
Pay attention to the instructor.
Get some sleep. I was not prepared for ctf day. I was so tired, that I kept mistyping stuff. Simple stuff. I wasn't going into the right directory to run things.
Plan out the tools you will use wisely, and put them in the $PATH. This isn't always recommended for production machines, but in the case of VMs in a ctf, this may be a good idea.
Make notes of the tools you used throughout the week. This will not only help you remember what to use, but will also be a handy reference guide for when you're nervous during the ctf. This way, you don't have to flip through the course books. This is also good advice for taking the exam - indexing.
Choose your team wisely. I socially engineered my way into a good team. I took a gamble and I wore my SANS Netwars Tournament of Champions t-shirt and hoodie this week. The instructor made sure to announce that I was in last year's ToC, so people naturally assumed that I probably knew stuff. I was asked to join the team that I wanted. (After my performance yesterday, they are probably wondering how I won NetWars. I wasn't dishonest. It was persistence, Googling, and luck.)
That being said, don't wait for someone to ask you. You should have your team made by Day 4 at the latest.
Watch the people in class. The quiet ones who aren't paying attention are wild cards. They will either be extremely good, or they will be bad. I lucked out. The quiet person in our class was really good.
You want people with different skill sets in your team. I was doing scanning/recon, taking notes - making sure we had good material for a report, cracking passwords because I threw a couple of cores and more memory into my vm. If there was a tie, we'd have to explain how we did things, and sometimes that report is what sets you apart.
The other guys were methodically working on exploiting the machines. I would go in behind them and see if we missed anything. You can scan from each system's perspective. You might see something different from that perspective, because certain machines may be able to talk to each other, and nothing else.
I still ended up rooting a box, because I went in behind the first wave of exploiters in our team and got root on the box while they were trying to get into the next box. You don't always need root, but it's nice to have to be able to get the hashes and crack them.
Don't compete with your teammates. You're there to work as a team, not be the "star".
If you get stuck, this sounds stupid, try the dumbest things you can think of first and work your way up. Example: In tech support, it would be, "Is it powered on? Are the cables plugged in on both ends?", etc. In pen testing, it would be "Is the username set to "password" or other passwords you might already know? Do users have more privileges than they should?, etc." Good privilege escalation guide here: https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation and here: https://www.fuzzysecurity.com/tutorials/16.html
Scan the network. Other teams may give clues about what to do next. They may be stuck in a spot that you already have and vice versa.
My team ended up winning, but just barely. I received a beautiful coin to add to my collection. Thus far, I have 2 504 coins, 1 560 coin, and a NetWars coin.
Choose the hotel you stay at wisely. I didn't sleep very well all week. There's always the chance of not sleeping well, but in this case, it was worse than usual. I can't fault the hotel; the beds were comfortable, the rooms were clean, etc. There was just so much noise around, the whole night. I did not stay in the SANS venue this time.
The class itself was great. The instructor was entertaining. He went a little fast, but he had a lot of material to cover. As usual, I was trying to take notes while he spoke. I'm glad I have On-Demand so I can listen to the lecture again from someone else's perspective and pause it when I feel the instructor is going too fast.
Feel like I learned a bit this week. Most of the learning was from doing dumb things.
There is a ctf in it. I can't give away exact answers. Here's a few tips:
Pay attention to the instructor.
Get some sleep. I was not prepared for ctf day. I was so tired, that I kept mistyping stuff. Simple stuff. I wasn't going into the right directory to run things.
Plan out the tools you will use wisely, and put them in the $PATH. This isn't always recommended for production machines, but in the case of VMs in a ctf, this may be a good idea.
Make notes of the tools you used throughout the week. This will not only help you remember what to use, but will also be a handy reference guide for when you're nervous during the ctf. This way, you don't have to flip through the course books. This is also good advice for taking the exam - indexing.
Choose your team wisely. I socially engineered my way into a good team. I took a gamble and I wore my SANS Netwars Tournament of Champions t-shirt and hoodie this week. The instructor made sure to announce that I was in last year's ToC, so people naturally assumed that I probably knew stuff. I was asked to join the team that I wanted. (After my performance yesterday, they are probably wondering how I won NetWars. I wasn't dishonest. It was persistence, Googling, and luck.)
That being said, don't wait for someone to ask you. You should have your team made by Day 4 at the latest.
Watch the people in class. The quiet ones who aren't paying attention are wild cards. They will either be extremely good, or they will be bad. I lucked out. The quiet person in our class was really good.
You want people with different skill sets in your team. I was doing scanning/recon, taking notes - making sure we had good material for a report, cracking passwords because I threw a couple of cores and more memory into my vm. If there was a tie, we'd have to explain how we did things, and sometimes that report is what sets you apart.
The other guys were methodically working on exploiting the machines. I would go in behind them and see if we missed anything. You can scan from each system's perspective. You might see something different from that perspective, because certain machines may be able to talk to each other, and nothing else.
I still ended up rooting a box, because I went in behind the first wave of exploiters in our team and got root on the box while they were trying to get into the next box. You don't always need root, but it's nice to have to be able to get the hashes and crack them.
Don't compete with your teammates. You're there to work as a team, not be the "star".
If you get stuck, this sounds stupid, try the dumbest things you can think of first and work your way up. Example: In tech support, it would be, "Is it powered on? Are the cables plugged in on both ends?", etc. In pen testing, it would be "Is the username set to "password" or other passwords you might already know? Do users have more privileges than they should?, etc." Good privilege escalation guide here: https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation and here: https://www.fuzzysecurity.com/tutorials/16.html
Scan the network. Other teams may give clues about what to do next. They may be stuck in a spot that you already have and vice versa.
My team ended up winning, but just barely. I received a beautiful coin to add to my collection. Thus far, I have 2 504 coins, 1 560 coin, and a NetWars coin.
Monday, June 18, 2018
NetWars Tournament of Champions/Imposter Syndrome
Someone was asking for help on the Advisory Board regarding NetWars. I posted about NetWars before, but I didn't post anything about the Tournament of Champions. I found an article written by someone who'd gotten a coin at SANS Rocky Mountain. This person told me that I'm inspirational because I'd won that tournament at SANS Rocky Mountain.
I was avoiding this post because I'm not really proud of my performance at the tournament that I won at and ToC. Some people say that I should just be proud for attending ToC. I didn't feel like I had to do much to get the invite - like it was a lucky break. Don't misunderstand; I learned a lot from NetWars Core Tournament 4 and NetWars continuous, but I wouldn't consider myself a "champion".
People talk about imposter syndrome - some have said that they think that I have it because I have trouble accepting compliments or acknowledging my accomplishments. What if how I feel is real, though? What if people really do assume I know more than I really do? I'm not saying that I can't learn. I'm saying that I still have a lot to learn, and that's ok. Right now, I'm learning blue team stuff because I've been promoted to a Security Analyst position. I thought that I had a lot of stuff to learn before - I'm stacking more plates onto that pile.
Hope to attend NetWars Tournament again soon.
Tips for ToC:
Mr. Skoudis - at the special meeting beforehand - will say, "Work in teams." I didn't follow his advice - my goal was not to win. I wanted to learn. However, if you want to win - join a team. I didn't because I didn't want to weigh my team down. It was my first time playing Netwars Core Tournament 5. In fact, just do exactly what Skoudis says prior to the game.
Other than that, follow the advice for normal NetWars Core Tournament.
Go with the goal of having fun - not winning - and it will be much more enjoyable. I love all of the story line in these tournaments - they keep it interesting. Love the music.
Good luck.
I was avoiding this post because I'm not really proud of my performance at the tournament that I won at and ToC. Some people say that I should just be proud for attending ToC. I didn't feel like I had to do much to get the invite - like it was a lucky break. Don't misunderstand; I learned a lot from NetWars Core Tournament 4 and NetWars continuous, but I wouldn't consider myself a "champion".
People talk about imposter syndrome - some have said that they think that I have it because I have trouble accepting compliments or acknowledging my accomplishments. What if how I feel is real, though? What if people really do assume I know more than I really do? I'm not saying that I can't learn. I'm saying that I still have a lot to learn, and that's ok. Right now, I'm learning blue team stuff because I've been promoted to a Security Analyst position. I thought that I had a lot of stuff to learn before - I'm stacking more plates onto that pile.
Hope to attend NetWars Tournament again soon.
Tips for ToC:
Mr. Skoudis - at the special meeting beforehand - will say, "Work in teams." I didn't follow his advice - my goal was not to win. I wanted to learn. However, if you want to win - join a team. I didn't because I didn't want to weigh my team down. It was my first time playing Netwars Core Tournament 5. In fact, just do exactly what Skoudis says prior to the game.
Other than that, follow the advice for normal NetWars Core Tournament.
Go with the goal of having fun - not winning - and it will be much more enjoyable. I love all of the story line in these tournaments - they keep it interesting. Love the music.
Good luck.
Saturday, March 10, 2018
HackyEaster-Teaser
I didn't know about this challenge, but apparently there is a challenge that is released annually around Easter time. You may want to check it out. It's here:
https://hackyeaster.hacking-lab.com
I completed the teaser challenge several days ago. I'm looking forward to seeing what they come up with for the rest of the challenge.
Be patient with the creators. Apparently it can take some time for them to judge the answers so you can move on, and they are people that volunteer to do so. Thanks to those people that put time into judging the submissions. :)
https://hackyeaster.hacking-lab.com
I completed the teaser challenge several days ago. I'm looking forward to seeing what they come up with for the rest of the challenge.
Be patient with the creators. Apparently it can take some time for them to judge the answers so you can move on, and they are people that volunteer to do so. Thanks to those people that put time into judging the submissions. :)
Subscribe to:
Posts (Atom)