Tuesday, 14 October 2014

NUS SoC Hacking Challenge 2 - Search For Me

Challenge 2 - Search For Me.

So this is what i see. 2 images and enter the text value. 

I have to be honest, this was not easy. If i had not been given a tip, i would never would have found the answer to this challenge. So what i did first was to identify what these pictures and how they might be related. Saved the first image on my Desktop.

Then, thanks to Google Image search, i uploaded the image and let Google search for whatever answer it could find.

Pretty much, the first clue. The image is actually a band called Peppermint Creeps.

Next, is this creepy image of a Doll. Like what i did above, i could not find a proper relation to this image and to the band. However, when i looked at the name of the image file, the name was 'brokendoll.jpg'.


Searching on Google using the term 'Perppermint Creeps' and 'Broken Doll', the above image was what i noticed. Something that can be related in the information security affairs. But first, as part of my analysis, i listened and read the lyrics and watched the video clips from both 'Broken Dollz' and 'Heartbleed' but yeah, it was a waste of time. It didn't help - but good songs though.


Guessing that the 'Heartbleed' term could be my next clue, i went to the Heartbleed website and noticed a string of characters that i would perhaps guessed to be the flag. At first, i input only the numbers without the dashes, nothing, then the numbers with the dashes - still nothing and then i copied the whole CVE-2014-0160 string and pasted it to the form.

And when i clicked Submit. Oh yeah!!!! Level 2 Owned!!!!

Next Stop - Level 3!

Monday, 13 October 2014

NUS SoC Hacking Challenge 1 - Unlock Me

So the NUS (National University of Singapore) SoC (School of Computing) had this initiative to create an online Hacking Challenge that is open to the public. I was notified of this from an email and a Facebook PM from my colleague and ex-colleague. So i decided to give it a go.

Here is the Mission 'Statement'. Pretty Awesome if you ask me.


Level 1 Challenge: Unlock Me

This was the first challenge, gotta admit, it wasn't easy for me actually. So you only have the Username and Password to Login and thats basically is the flag to capture. 

First things first, i looked for any hardcoded credentials and this usually can be found in the page source. 

Analysing the page source, i find only what seems to be a Username. Upon further analysis, there's no passwords that can be found. That's it, im done...for a while..

Then i noticed the 'Forgot Password'. Hmm..... looks interesting. 

And when i clicked on it, it asked for the Username. Wait! We do have a Username! Input the username and type in 'Get Password'

Password is sent to the registered email! But wait, i did not provide any email in the first place. Taking a look at the URL, i see the good old Parameter values. Yeap, there's a parameter called 'emailid=' and its using 'demo@example.com'.

So the next step is to test by putting in my valid email address and execute the URL. Again, Password successfully sent.

To test if this works, i logged into my email address and fair enough, the password is provided!

With the received password, input both the username and password and click Login. Oh yeah! Houston, we just successfully captured the first flag!!!

Onto the next Level!!!!

Friday, 26 September 2014

SecureSingapore - an (ISC)2 event

Was privileged to be invited to speak at SecureSingapore yesterday, an event that was held right after GovWare. This was my first time to give a full presentation at a Singapore-based conference. Previously when i presented in ABS-FITA and WebSense (both in Singapore), i was doing the technical demo but this time i had a whole hour to speak. My speaking experience from conferences in India, UAE and US gave me the confidence to speak in this.



 
The topic of my talk. Unlike Defcon Kerala and The Hackers Conference in India and BSidesLV in Vegas, i need to ensure that my talk covers more on a holistic view of SCADA and Critical Infrastructure and little on the low level technical side. 



I had a great time presenting to a room full of CISSP certified professionals and security practitioners. I was also delighted to get some laughs and response from the crowd. One of the things i did was to demonstrate the way Stuxnet works and got 3 volunteers from the crowd to assist me in illustrating it.

At the end of my talk, i had a chance to meet and greet people from industries such as banks and product vendors. One of them was the President of ISC2 Singapore himself!  This was a new experience for me and i certainly thank BT and ISC2 for giving me the privilege to share my knowledge to the industry experts.

And what better way to be given the thumbs up than to receive such an honest feedback from one of the audience.




Singapore Governmentware 2014

Attended Govware recently which was held in Suntec City Convention Center on the 23rd - 25th of September.



Had a lot of great talks but of course dont expect the kind of Defcon or BSides Technical talks as these were more focused to decision makers as well as C & S level people on the latest emerging technologies that would assist them to protect their organizations.

And since i have this interest in Critical Infrastructure and SCADA, i attended the following tracks which provided a holistic view of the Critical Infrastructure issues and how their products or services can assist organizations.










One of the things i liked about Govware is the Cyber challenge CTF event that allow students and hacking enthusiasts to participate and test their hacking skills. As a past CTF participant myself, i know the pressure and the fun involved in such events.. whoever the winner will definitely has something to brag about!








And of course, the many vendors and product booths. Some showed awesome demonstrations, some provided free Tshirts, stickers and USB sticks!





















And yeah, thats me having a selfie at Govware! ;)