From 799d729f2cb57cc262e5bdd1926d4e0630248997 Mon Sep 17 00:00:00 2001 From: thomashaw Date: Wed, 16 Aug 2017 18:06:06 +0100 Subject: [PATCH] renamed guildford_event_basic_narrative.xml => basic_narrative.xml --- ...c_narrative_v2.xml => basic_narrative.xml} | 47 +- .../ctf/guildford_event_basic_narrative.xml | 543 ------------------ 2 files changed, 14 insertions(+), 576 deletions(-) rename scenarios/ctf/{guildford_event_basic_narrative_v2.xml => basic_narrative.xml} (91%) delete mode 100644 scenarios/ctf/guildford_event_basic_narrative.xml diff --git a/scenarios/ctf/guildford_event_basic_narrative_v2.xml b/scenarios/ctf/basic_narrative.xml similarity index 91% rename from scenarios/ctf/guildford_event_basic_narrative_v2.xml rename to scenarios/ctf/basic_narrative.xml index c3c28d1f5..f83d009e9 100644 --- a/scenarios/ctf/guildford_event_basic_narrative_v2.xml +++ b/scenarios/ctf/basic_narrative.xml @@ -4,34 +4,12 @@ xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.github/cliffe/SecGen/scenario"> - + system - - - - - - dangerous_store.co.uk - - - - 1337 - - - - @@ -218,9 +196,7 @@ - - - + @@ -256,7 +232,7 @@ Log into the server and check your mail. - Username: + Username: accounts Password: accounts @@ -323,10 +299,15 @@ To whom this may concern, Now that you're on the server, we need your help with our investigation. - We've managed to hide this account on the server for you. Criminal activity has been taking place, particularly over port 1337. - Our initial examinations lead us to believe that the perpetrators use poor security practices. + We've managed to hide this account on the server for you. Criminal activity has been taking place, + particularly over port 1337. + + Our initial examinations lead us to believe that the perpetrators use poor security practices. + Find out if the suspects have user accounts on this server and see if you can break in. - We need all the evidence we can get. In the form of flags. The more you collect the stronger our case will be. + We need all the evidence we can get. In the form of flags. The more you collect the stronger our case + will be. + Godspeed, Detective Jones. @@ -346,8 +327,8 @@ accounts - - store_domain + + dangerous_store.co.uk accounts @@ -412,7 +393,7 @@ - store_port + 1337 store_domain diff --git a/scenarios/ctf/guildford_event_basic_narrative.xml b/scenarios/ctf/guildford_event_basic_narrative.xml deleted file mode 100644 index f522fde54..000000000 --- a/scenarios/ctf/guildford_event_basic_narrative.xml +++ /dev/null @@ -1,543 +0,0 @@ - - - - - - - - system - - - - - - - - dangerous_store.co.uk - - - - 1337 - - - - - - ceaseless_daughter - - - - - - - - creepy_fly - - - - icky-company - - - - - - - - 1_username - - - 1_password - - - missing_persons_report - - - *** Missing Persons Report *** - Two individuals are missing. No names or dates attached to the report. - If you can find out who has gone missing and when, you will be rewarded for your efforts. - Enter their names in the format flag{Firstname Lastname YYYY-MM-DD HH:MM:SS} - If you find any more evidence, such as the name of a suspect, use the format flag{Firstname Lastname} - - - - - - - - 2_username - - - - - - - - - - - - - - 3_username - - - - - - - - - - - - - 2_account - - - - - - - - - - - 3_account - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 3 - 4 - 5 - - - - - - - - 2 - 3 - 4 - 5 - - - - - - - - 2_person_name - 3_person_name - 1_store_person_name - 2_store_person_name - 3_store_person_name - - - murderer_id - - - - - - - - murderer_id - dealer_id - - - 2 - 3 - 4 - 5 - - - - - - - - murderer_id - dealer_id - 1_murdered_id - - - 2 - 3 - 4 - 5 - - - - - - - - 2_person_name - 3_person_name - 1_store_person_name - 2_store_person_name - 3_store_person_name - - - 1_murdered_id - - - - - - - - 2_person_name - 3_person_name - 1_store_person_name - 2_store_person_name - 3_store_person_name - - - 2_murdered_id - - - - - - - - mysql_datetime - - - - - - - - mysql_datetime - - - - - - - - - - murderer_name - - - - - - - 1_murdered_name - 1_murdered_timestamp - - - - - 2_murdered_name - 2_murdered_timestamp - - - - - - - - - - - 1_account - - - - - - 1_account - - - - Make a note of the technique used to solve this challenge as it will come in handy again soon. - - - - - - 2_account - - - - - - - - We need your help! - - - You have received a strange message. Can you decode it to read the contents? - - - - Log into the server and check your mail. - Username: - 1_username - Password: - 1_password - Here's a flag for your efforts. - - - - - - - - - - <a href="oops.html"/> - - - - oops.html - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - detective_jones - - - police.gov.uk - - - 1_username - - - Investigation Information - - - To whom this may concern, - Now that you're on the server, we need your help with our investigation. - We've managed to hide this account on the server for you. Criminal activity has been taking place, particularly over port 1337. - Our initial examinations lead us to believe that the perpetrators use poor security practices. - Find out if the suspects have user accounts on this server and see if you can break in. - We need all the evidence we can get. In the form of flags. The more you collect the stronger our case will be. - Godspeed, - Detective Jones. - - - - - 12/06/2017 14:51:03 - - - mail - - - - - - - - 3_username - - - store_domain - - - 2_username - - - New order required - - - Good news, I've been getting rid of loads of gear lately. The customers are mad for it. - We're going to need a new order ASAP! - - - - - 17/06/2017 20:12:35 - - - mail - - - - - - - - - hitman - - - store_domain - - - 3_username - - - Offed the last one - - - Job done! The last one on the list is now swimming with the fishes. - It wasn't clean though, I think I saw someone watching in the distance. - Not that it matters. They'll never catch us! - - - - - 19/06/2017 23:58:12 - - - mail - - - - - - - - - - - 3_account - - - - - - store_port - - - store_domain - - - 2_person - 3_person - 1_store_person - 2_store_person - 3_store_person - - - dealer_id - - - murderer_id - - - 1_murdered_timestamp - 2_murdered_timestamp - - - 1_murdered_id - 2_murdered_id - - - - - - - - - tiaspbiqe2r - - - - - \ No newline at end of file