Showing posts with label cyber readiness challenge. Show all posts
Showing posts with label cyber readiness challenge. Show all posts

Tuesday, 19 November 2013

Hunting and Hacking MSSQL Servers - Published Article on PenTestMag.com

Me and my colleague wrote an article about how to pentest MSSQL end to end. As pentesters, we are always constantly researching on how to make our lives easier when performing ethical hacking engagements structurally and ensure that all possible methods are used based on methodologies such as OSSTMM.

We spent about a week browsing through the web and compile what could be done to properly assess a MSSQL server/services and sat down and test it on our testing servers (knowing that most customers do not allow us to exploit the systems).

So once we wrote the article, we send it to PenTestMag.com for review and cross our fingers hoping it will be reviewed and accepted. Fair enough, upon review, we had to elaborate, add, edit and explain the methods used so it will be easy for readers to understand and technically possible to follow on a step by step basis.

Hence, after all our hard work, it was finally accepted and a month later, it got published! So ladies and gentlemen, i present you some snapshots of the article! :)



The cover of the magazine


My Colleague and myself on the cover!

The content page


The first page of the article


The end of the article and our brief bio.


The article can be downloaded at:




Wednesday, 13 November 2013

Winners of Symantec Cyber Readiness Challenge (Cloud Asia Expo, Singapore)

Finally we emerged as Champion!!!!
There were about 25 participants. Some grouped in 2, others went solo. But i have to say that this was a very very very tough CTF unlike the first Cyber Readiness Challenge where we got the first runner up.

This time, the organizers came prepared. There were no wireless network at the location and participants were encouraged to bring their 3/4G dongle. Me on the other hand totally forgot about it and luckily, the organizers brought some spares in case there are those people who forgot (me).

Started with a video showing the story of the situation. Once the clock starts, the challenge begins! Heck, it was one tough ride. Started with a flag that you need to be forensically knowledgable and of course, one must know LINUX!!! We took almost half an hour to figure out the first flag. But after that, it went to become tougher. Glad i used nmap to scan the whole network for live machines and start finding vulnerabilities and poking their ports. It was not as straight forward as i thought it would be.

Nevertheless, we managed to bring back glory by becoming the champion of the tournament and again, a very very tiring 4 hours event. We didnt even managed to have our breakfast. Just a cup of mineral water and a cup of coffee and off we go, non stop action.......

Kudos to Symantec Singapore for organizing such a wonderful event. I really hope Symantec will continue to organize such event in future and allow potential hackers to participate and challenge themselves in the given environment to hack, steal and win -----legally of course !

Event: Cloud Asia Expo
Competition: Symantec Cyber Readiness Challenge
Location: Suntec City Convention Center
Country: Singapore

Check out the photos:




The partnership of the Hulk and Juggernaut

Working towards winning

The 2nd Placed Winners

The First Place Winners!


Previous Symantec CRC Participation:
First Runner Up in the first ever APAC Symantec Cyber Readiness Challenge: 




Wednesday, 6 November 2013

Symantec Cyber Readiness Challenge is Back in Singapore

"Symantec Security hosts the Cyber Readiness Challenge - an interactive 'capture the flag' style competition modelled after real-life security issues – at Cloud Expo Asia 2013.

The challenge positions participants as cyber security experts who will compete for system penetration within a simulated environment set with diverse and realistic vulnerabilities.

Within a fictitious scenario, participants will face challenges of increasing complexity and difficulty as they move through the various stages of a security breach."

Conference cum CTF



Register Here

For more information about Symantec's CRC
Link: http://www.symantec.com/page.jsp?id=cyber-readiness-challenge

Watch the introductory video about Symantec's CRC


Friday, 20 September 2013

Symantec Cyber Readiness Challenge - First in Asia (Singapore)

BT got second place in the Symantec Cyber Readiness Challenge- CTF Hacking Competition!



The CTF competition was not something we expected. Before that day, we spent countless nights familiarizing ourselves with Kali and BackTrack and focusing solely on the Network hacking. Of course, we performed our recon in finding out more about similar CTFs by other organizers in the past such as from DEFCon, HITB, Black Hat and read what sort of challenges await us.

So when we arrived, we were quite shocked to see players from big named companies and also from the Big Four joining which made us humble seeing their presence but then again... hackers constantly challenge one another and thats when the fun started!

As a rule of thumb, we cant expose the content of the competition but for those who are joining the Symantec CRC competition, better get yourselves prepared with Web, Network and Database pentest. Be good with the tools used such as Metasploit and NMAP.

It was a full 4 hrs competition that made us exhausted at the end of the hour. Unfortunately, there were also hiccups during the competition and as a personal advice: better use your own dongle rather than using the available made Wifi or LAN network.

We also experienced unethical hackers during capturing the flag. One of the rules is to NOT CHANGE anything that will not allow other players to compete and one of the teams were literally changing the passwords of the accounts they cracked which if reported could be disqualified. There were some tug of war to control the system each one kicking a session from one another.

It was tough but eventually we nailed it. We got second spot and the winner got a Flag more than us! Damn it! But all in all, this was indeed a fun competition that allowed us to hack/crack/pentest a real world scenario...


The BT Team


The Banner

Another huge Banner 

WE ARE THE second placed WINNER! 

The Trophy 

The Team-Up