<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Security Training</title>
	<atom:link href="http://www.information-security-training.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.information-security-training.com</link>
	<description>Tactical Network Security Courses and Certifications</description>
	<lastBuildDate>Thu, 24 Jun 2010 15:45:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>HSIYF 2 for Charity &#8211; Solutions!</title>
		<link>http://www.information-security-training.com/news/hsiyf-2-for-charity-solutions/</link>
		<comments>http://www.information-security-training.com/news/hsiyf-2-for-charity-solutions/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 12:47:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[NEWS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=1070</guid>
		<description><![CDATA[The grueling 48 hour cyber challenge is over &#8211; leaving the contestants tired and bleeding. We had a GREAT event, and enjoyed seeing the participants engage in quality hacking!
Without any further delay, we would like to congratulate the official winners of HSIYF 2 for charity:
1st place &#8211; Sinn3r
2nd place &#8211; TecR0c
You can read their solutions [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><img class="alignright" title="HSIYF 2" src="http://www.information-security-training.com/images/hsiyf2-infosec.png" alt="" width="235" height="127" />The grueling 48 hour cyber challenge is over &#8211; leaving the contestants tired and bleeding. We had a GREAT event, and enjoyed seeing the participants engage in quality hacking!</p>
<p style="text-align: justify;">Without any further delay, we would like to congratulate the official winners of HSIYF 2 for charity:</p>
<p style="text-align: justify;"><span style="color: #ff0000;">1st place &#8211; Sinn3r</span></p>
<p><span style="color: #ff0000;">2nd place &#8211; TecR0c</span></p>
<p>You can read their solutions <a title="HSIYF2 solution" href="http://www.information-security-training.com/report_final_hsiyf2.pdf" target="_blank">here</a> and <a title="HSIYF2 solution 2" href="http://tecninja.net/blog/?p=198" target="_blank">here</a>.</p>
<p>We would also like to thank EVERYONE who helped and participated in this event. Till next time!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/news/hsiyf-2-for-charity-solutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Let the games begin &#8211; again!</title>
		<link>http://www.information-security-training.com/events/let-the-games-begin-again/</link>
		<comments>http://www.information-security-training.com/events/let-the-games-begin-again/#comments</comments>
		<pubDate>Sat, 19 Jun 2010 12:53:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[EVENTS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=1021</guid>
		<description><![CDATA[The cyber hacking challenge - "How Strong is your Fu for Charity" has begun! All contestants have received emails with login credentials, and should download the VPN certificates from their control panel page. You can log in to the control panel using the same credentials. The gates have been opened!]]></description>
			<content:encoded><![CDATA[<h2><span style="color: #ff6600;">It Has Begun!</span></h2>
<p>The cyber hacking challenge &#8211; &#8220;How Strong is your Fu for Charity&#8221; is about to begin! All contestants have received emails with login credentials, and should download the VPN certificates from their control panel page. You can log in to the control panel using the same credentials. The gates will soon be opened!</p>
<h3><span style="color: #ff9900;">General info:</span></h3>
<ul>
<li style="text-align: justify;"> The tournament will last for 48 hours.</li>
<li style="text-align: justify;">There are 5 machines in each challenge room, each machine contains a &#8220;proof.txt&#8221; file on the administrator or root desktops. Discovery of each proof file provides 20 points.</li>
<li style="text-align: justify;">The first to reach 100 points wins a free BlackHat Vegas ticket. The second to reach 100 points wins an online CTP course.</li>
<li style="text-align: justify;"><span style="color: #ffff00;">Attendees, please join our IRC channel on freenode &#8211; #HSIYF.</span></li>
</ul>
<h3><span style="color: #ff9900;">Challenge rules:</span></h3>
<ul>
<li style="text-align: justify;"><span style="color: #ff0000;">Respect your fellow hackers &#8211; do not change configurations of machines once compromised.</span></li>
<li style="text-align: justify;">This includes changing of passwords, deleting files or otherwise making the challenge machines unavailable to others.</li>
<li style="text-align: justify;">You may not change your VPN IP address</li>
<li style="text-align: justify;">You may not ARP spoof or preform any layer 2 attacks</li>
<li style="text-align: justify;">Avoid bruteforce attacks, they will get you nowhere.</li>
</ul>
<p>We would like to thank you all for registering to this tournament and contributing to the HFC. We wish you all an enjoyable and challenging event!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/events/let-the-games-begin-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HSIYF For Charity &#8211; Registration</title>
		<link>http://www.information-security-training.com/events/hsiyf-for-charity-registration-page/</link>
		<comments>http://www.information-security-training.com/events/hsiyf-for-charity-registration-page/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 18:41:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[EVENTS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=934</guid>
		<description><![CDATA[Our second cyber hacking challenge from Offensive Security is on it's way. Registration to "How Strong is your Fu - For Charity" has begun!]]></description>
			<content:encoded><![CDATA[<h2 style="text-align: justify;"><span style="color: #ff6600;">Hack For Charity!</span></h2>
<p style="text-align: justify;">Our second <a title="Cyber Hacking Challenge" href="http://www.offensive-security.com/offsec/cyber-hacking-challenge-2-hsiyf-for-charity/" target="_blank">cyber hacking challenge</a> from Offensive Security is on it&#8217;s way. Registration to &#8220;How Strong is your Fu &#8211; For Charity&#8221; has begun! Offsec has teamed up with the crew at <a title="Hackers for Charity" onclick="javascript:pageTracker._trackPageview('/outbound/article/johnny.ihackstuff.com');" href="http://johnny.ihackstuff.com/">Hackers For Charity</a> and the world’s premier Hacker Con – <a title="BlackHat Hacker Conferences and Training" onclick="javascript:pageTracker._trackPageview('/outbound/article/www.blackhat.com');" href="http://www.blackhat.com/">BlackHat</a>, to provide another amazing Cyber Hacking Challenge with a whole new level of pain.  <span style="color: #ffff00;">Our goal is to raise $5000 for HFC</span> as well as provide a world class cyber hacking event. <span style="color: #ff0000;">The prizes?</span> 1st place gets a<span style="color: #ff0000;"> BlackHat Vegas Conference Ticket</span> (no travel included) , 2nd place gets a <span style="color: #ff0000;">CTP Online Course</span> from Offensive Security. Wowz!<span style="color: #ff0000;"> </span></p>
<p style="text-align: center;"><a href="http://www.information-security-training.com/images/hsiyf2-infosec.png"><img class="aligncenter" title="HSIYF For Charity" src="http://www.information-security-training.com/images/hsiyf2-infosec.png" alt="HSIYF cyber hacking challenge" width="480" height="260" /></a></p>
<p style="text-align: justify;">Unlike our previous challenge, seats to this tournament will be limited, and require a registration fee of <span style="color: #ff0000;">49.00 $US</span>. All proceeds from this event go to the HFC, and their efforts in East Africa.</p>
<h2 style="text-align: justify;"><span style="color: #ff6600;">What to expect?</span></h2>
<p style="text-align: justify;">The event will take place on June 19th, 2010 and will last for 48 hours. Since this contest is not for all the public, we have sent the n00b filter to a retirement facility in the deep south and set up a new level of challenge for you.  Contestants will have to combat with hardened web applications, fuzz unknown protocols and programs and write custom exploits.  This is just scratching the surface of what you will face to win the awesome prizes!</p>
<p style="text-align: justify;">
<h2 style="text-align: justify;"><span style="color: #ff6600;">The Registration Process</span></h2>
<p style="text-align: justify;">Once payment is approved, you will receive a confirmation mail from PayPal and your registration will be complete. On the 18th of June, you will receive a VPN connectivity pack to our Tournament servers by email. On June 19, our blog will announce the beginning of the tournament (around 14:00 GMT), and all hell will break loose.</p>
<p style="text-align: justify;"><span style="color: #ff0000;">Please note that the connectivity packs will be sent to your PAYPAL email address (the one used by your PayPal account). </span></p>
<p style="text-align: justify;">
<h2 style="text-align: justify;"><span style="color: #ff6600;">REGISTRATION CLOSED!</span></h2>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/events/hsiyf-for-charity-registration-page/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>HSIYF Runner up Documentation</title>
		<link>http://www.information-security-training.com/news/hsiyf-runner-up-documentation/</link>
		<comments>http://www.information-security-training.com/news/hsiyf-runner-up-documentation/#comments</comments>
		<pubDate>Thu, 13 May 2010 05:01:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[NEWS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=792</guid>
		<description><![CDATA[As mentioned in our previous blog post, we really had a rough time selecting the winners of HSIYF #1. We took into account two main factors &#8211; speed of completion and presentation of documentation. In the professional world of Penetration Testing, all the technical aspects of a penetration test mean little if you cannot convey [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">As mentioned in our previous blog post, we really had a rough time selecting the winners of HSIYF #1. We took into account two main factors &#8211; speed of completion and presentation of documentation. In the professional world of Penetration Testing, all the technical aspects of a penetration test mean little if you cannot convey your findings properly to the clients. We would like to present the awesome work of our top 10 contestants, in the order of completion of the tournament:</p>
<ul style="text-align: justify;">
<li style="text-align: justify;"><a href="http://www.information-security-training.com/documentation/01-snowytoxa.pdf">snowytoxa</a> (14:52 h)</li>
<li><a href="http://www.information-security-training.com/documentation/02-kyprizel.txt">kyprizel</a> (14:53 h)</li>
<li><a href="http://www.information-security-training.com/documentation/03-touzoku.pdf">touzoku</a> (15:13 h)</li>
<li><a href="http://www.information-security-training.com/documentation/04-vadium.pdf">vadium</a> (15:26 h)</li>
<li>depth (25:45 h)</li>
<li><a href="http://www.information-security-training.com/documentation/04-dnet.pdf">dnet </a>(25:51 h)</li>
<li><a href="http://www.information-security-training.com/documentation/06-woff.pdf">woff</a> (34:29 h)</li>
<li><a href="http://www.information-security-training.com/documentation/07-painsec.pdf">painsec </a>(38:18 h)</li>
<li><a href="http://www.information-security-training.com/documentation/08-raph0x88.pdf">raph0&#215;88</a> (40:14 h)</li>
<li><a href="http://www.information-security-training.com/documentation/09-ipax.pdf">ipax</a> (40:14 h)</li>
<li><a href="http://www.information-security-training.com/documentation/11-ace1.pdf ">ace1</a> (41:46 h)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/news/hsiyf-runner-up-documentation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SMTX Ghost Challenge Video Solution</title>
		<link>http://www.information-security-training.com/videos/smtx-ghost-challenge-video/</link>
		<comments>http://www.information-security-training.com/videos/smtx-ghost-challenge-video/#comments</comments>
		<pubDate>Wed, 12 May 2010 05:37:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[VIDEOS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=783</guid>
		<description><![CDATA[SMTX submitted his solution to our &#8220;ghost&#8221; machine. Watch and enjoy :)

]]></description>
			<content:encoded><![CDATA[<p>SMTX submitted his solution to our &#8220;ghost&#8221; machine. Watch and enjoy :)</p>
<p><object type="application/x-shockwave-flash" data="http://vimeo.com/moogaloop.swf" width="500" height="375"><param name="allowscriptaccess" value="always"/><param name="allowfullscreen" value="true"/><param name="movie" value="http://vimeo.com/moogaloop.swf"/><param name="flashvars" value="clip_id=11680637&#038;server=vimeo.com&#038;fullscreen=1&#038;show_title=1&#038;show_byline=1&#038;show_portrait=1&#038;color=00ADEF"/></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/videos/smtx-ghost-challenge-video/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>HSIYF Offensive Security Report &#8211; 1 of 3</title>
		<link>http://www.information-security-training.com/news/offsec-hsiyf-report-part1/</link>
		<comments>http://www.information-security-training.com/news/offsec-hsiyf-report-part1/#comments</comments>
		<pubDate>Wed, 12 May 2010 05:23:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[NEWS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=752</guid>
		<description><![CDATA[This is the first of 3 official result posts we will be writing for the HSIYF tournament.
Introduction
A couple of weeks ago, we decided to create a unique Hacking Tournament under the name “How Strong is your Fu” (HSIYF). We decided to use new vulnerable images we created for our PWB online course labs, and have [...]]]></description>
			<content:encoded><![CDATA[<p>This is the first of 3 official result posts we will be writing for the HSIYF tournament.</p>
<h2><span style="color: #ff6600;">Introduction</span></h2>
<p style="text-align: justify;">A couple of weeks ago, we decided to create a unique Hacking Tournament under the name “How Strong is your Fu” (HSIYF). We decided to use new vulnerable images we created for our PWB online course labs, and have the hacking community play with them. After a quick brainstorming session, we took a week to (re)discover our dark side and created the HSIYF challenge machines, <em>noob-filter</em>, <em>ghost</em> and <em>killthen00b</em>. This document will provide an overview of the challenge and describe possible attack vectors for each of the challenges presented.</p>
<h2 style="text-align: justify;"><span style="color: #ff6600;">Pre-challenge Preparations</span></h2>
<p style="text-align: justify;">Registration to the challenge was opened a couple of weeks before the challenge and the amount of sign-ups was overwhelming – way more than we expected. We didn’t want to disappoint the masses, and decided to design our challenges in a way that everyone would be able to participate – and so was born – “noob-filter.com”. The main concept behind the “noob filter” machine was to thin out all the registrations – only people whom could hack this challenge machine would be admitted into our VPN labs. Obviously, we immediately saw the flaw in this design – having over 1000 hackers run their favorite vulnerability scanner on this machine would spell doom to the initial challenge. We decided to deal with this in a nasty way – we installed a sensitive IPS, which would be triggered by such scanners. The IPS was configured for a 5-minute ban on the offending IP. This phase of the challenge was dubbed “Phase 1”.</p>
<h2 style="text-align: justify;"><span style="color: #ff6600;">HSIYF Event Overview</span></h2>
<p style="text-align: justify;">As the event started, we quickly realized we hadn’t taken into account several details:</p>
<ul style="text-align: justify;">
<li><span style="color: #ff9900;"><strong>Sending over 1000 emails using a Google Premium account:</strong></span></li>
</ul>
<p style="padding-left: 30px; text-align: justify;">Our initial mail blast took over 3 hours to send – many people got their mails late. We attempted to help those who contacted us by providing them the information via IRC.<strong> </strong></p>
<ul style="text-align: justify;">
<li><span style="color: #ff9900;"><strong>Expecting 1000 hackers to read the instructions from beginning to end:</strong></span></li>
</ul>
<p style="padding-left: 30px; text-align: justify;">In hindsight &#8211; an unrealistic expectation. Some participants were not native English speakers, while others simply didn’t RTFM.<strong></strong></p>
<ul style="text-align: justify;">
<li><span style="color: #ff9900;"><strong>Expecting 1000 hackers to abide by our rules:</strong></span></li>
</ul>
<p style="padding-left: 30px; text-align: justify;">Our “please do not damage the challenge machines” plea fell on deaf ears. We believe there was a general sense of “lack of accountability” – meaning that many participants did not care about leaving challenge machines in tact for others to enjoy.</p>
<ul style="text-align: justify;">
<li><span style="color: #ff9900;"><strong>Ignoring Mother’s day:</strong></span></li>
</ul>
<p style="padding-left: 30px; text-align: justify;">Some participants’ efforts were hampered by “Mothers day”…<strong></strong></p>
<p style="text-align: justify;">Thankfully, each of these oversights was managed in real time, with minimal impact to the tournament. No mothers were harmed during this tournament.</p>
<h2><span style="color: #ff6600;">Main difficulties encountered by contestants</span></h2>
<p style="text-align: justify;">The most overwhelming initial difficulty encountered by participants was the n00b filter IPS. The IPS threw almost everyone off, bringing up claims that “the servers were down” or that “the servers were real slow”. Neither of these observations was true. Eventually, people caught on, and started being more careful with traffic sent to the n00b filter machines. Generally speaking, we noticed a “sheep herd effect”, where a single wrong observation was reported in the IRC channel, and then repeated by others continuously, misleading the main mass of the contenders.</p>
<h2><span style="color: #ff6600;">Challenge Solutions</span></h2>
<p>The part you’ve all been waiting for – solutions to our challenge boxes.</p>
<h2><span style="color: #ff6600;">Noob filter</span></h2>
<p style="text-align: justify;">Our noob filter box was running Fedora 12, fully patched. Although the index page contained a login form, the machine itself was not running MySQL or PHP. The server was also running a vulnerable version of DotDefender – a WAF which contained an unpatched remote command execution vulnerability, described here: http://www.exploit-db.com/exploits/10261</p>
<p style="text-align: justify;">The described vulnerability is a POST authentication vulnerability, leading many to believe they needed to administrative password in order to exploit it. Our configured password was “password”, which we expected to be cracked and changed relatively quickly. In accordance to our expectations, this happened <strong>very</strong> fast, leaving other contestants “stranded”, complaining that “the password was changed” and therefore the vulnerability was “unavailable for them to exploit”.</p>
<p style="text-align: justify;">A quick examination of the DotDefender software (in a local lab…. did anyone download the software locally and try it out? Tsk Tsk …) should have revealed a 0day XSS vulnerability in the “Host Header” field of the HTTP request, allowing to create a “one two punch combination” resulting in unauthenticated remote command execution. <a title="Dotdefender XSS 0day " href="http://www.information-security-training.com/documentation/dotdefender.js.txt">Check out sample code here</a>. We will post part 2 and three in the next few days.</p>
<p style="text-align: center;"><a href="http://www.information-security-training.com/images/strongyourfuis.png"><img class="aligncenter" title="Strong your Fu is" src="http://www.information-security-training.com/images/strongyourfuis.png" alt="" width="356" height="112" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/news/offsec-hsiyf-report-part1/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>HSIYF #1 Tournament Results</title>
		<link>http://www.information-security-training.com/news/hsiyf-1-tournament-results/</link>
		<comments>http://www.information-security-training.com/news/hsiyf-1-tournament-results/#comments</comments>
		<pubDate>Wed, 12 May 2010 04:47:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[NEWS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=740</guid>
		<description><![CDATA[HSIYF Tournament Winners
After a couple of days of reading through submitted documentation, we are happy to announce the winners of the HSIYF Hacking Tournament #1. We did NOT have an easy time deciding the winners, as there were several elements factored in the results. The two main elements factored in were speed of completion (of [...]]]></description>
			<content:encoded><![CDATA[<h2 style="text-align: justify;"><span style="color: #ff6600;"><img class="alignright" title="HSIYF results" src="http://www.information-security-training.com/images/hsify-results.png" alt="" width="245" height="266" />HSIYF Tournament Winners</span></h2>
<p style="text-align: justify;">After a couple of days of reading through submitted documentation, we are happy to <a title="HSIYF" href="http://scoreboard.information-security-training.com/scoreboard/">announce the winners of the HSIYF Hacking Tournament </a>#1. We did NOT have an easy time deciding the winners, as there were several elements factored in the results. The two main elements factored in were speed of completion (of all the challenges) and the presentation of the results.</p>
<p style="text-align: justify;">So, without further ado we would like to announce <a title="HSIYF winner" href="http://www.information-security-training.com/documentation/04-vadium.pdf"><span style="color: #ff0000;">Vadium</span></a> and <a title="HSIYF winner" href="http://www.information-security-training.com/documentation/06-woff.pdf"><span style="color: #ff0000;">Woff</span></a> as the final winners of HSIYF #1. We will shortly publish our own review of the challenge. We would like to personally thank all those who participated and sent their results in.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/news/hsiyf-1-tournament-results/feed/</wfw:commentRss>
		<slash:comments>26</slash:comments>
		</item>
		<item>
		<title>How Strong is your Fu &#8211; Wrapping up</title>
		<link>http://www.information-security-training.com/news/how-strong-is-your-fu-wrapping-up/</link>
		<comments>http://www.information-security-training.com/news/how-strong-is-your-fu-wrapping-up/#comments</comments>
		<pubDate>Sun, 09 May 2010 11:18:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[NEWS]]></category>
		<category><![CDATA[bled]]></category>
		<category><![CDATA[fu]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[offensive]]></category>
		<category><![CDATA[participate]]></category>
		<category><![CDATA[scoreboards]]></category>
		<category><![CDATA[strong]]></category>
		<category><![CDATA[suffering]]></category>
		<category><![CDATA[tournament]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=730</guid>
		<description><![CDATA[As the time of the end of the hacking tournament comes closer, we would like to thank everyone who bled, suffered and participated. The experience was GREAT fun, on both sides, and we have decided to turn these events into an Offsec Tradition.
The tournament will end officially on Monday 14:00 GMT, when all servers will [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><a href="http://www.information-security.com/images/mama-704183.jpg"><img class="alignright" title="Mama" src="http://www.information-security.com/images/mama-704183.jpg" alt="" width="247" height="306" /></a>As the time of the end of the hacking tournament comes closer, <span style="color: #ff6600;">we would like to thank everyone who bled, suffered and participated</span>. The experience was GREAT fun, on both sides, and we have decided to turn these events into an Offsec Tradition.</p>
<p style="text-align: justify;"><span style="color: #ff6600;">The tournament will end officially on Monday 14:00 GMT</span>, when all servers will be shut down except for the scoreboard.</p>
<p style="text-align: justify;"><span style="color: #ff6600;">You will have 24 hours once the tournament ends to submit your documentation to our judge panel</span> &#8211; fu-at-offsec-dot-com.</p>
<p style="text-align: justify;">The scoreboard will be updated as we evaluate the documentation. If you choose to blog about your solution, we suggest you password protect your post, so that others wont mooch your solutions. Don&#8217;t forget to send us both the blog link and the password.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/news/how-strong-is-your-fu-wrapping-up/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Let the Games begin!</title>
		<link>http://www.information-security-training.com/events/hacking-tournament/</link>
		<comments>http://www.information-security-training.com/events/hacking-tournament/#comments</comments>
		<pubDate>Sat, 08 May 2010 01:29:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[EVENTS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=665</guid>
		<description><![CDATA[The &#8220;How Strong is your Fu&#8221; hacking tournament has officially begun. The hacking tournament will last for 48 hours &#8211; we wish you good luck! Everyone registered will get a chance to participate in &#8220;Phase 1&#8243; of the tournament. Please read the following very closely in order to make the best out of your experience [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><img class="alignright" title="How Strong is your FU" src="http://www.information-security-training.com/images/atom-bomb-1.png" alt="" />The &#8220;<span style="color: #ff0000;">How Strong is your Fu</span>&#8221; hacking tournament has officially begun. The hacking tournament will last for 48 hours &#8211; we wish you good luck! Everyone registered will get a chance to participate in &#8220;Phase 1&#8243; of the tournament. Please read the following very closely in order to make the best out of your experience :</p>
<p style="text-align: justify;"><span style="color: #ff6600;">&#8220;Phase 1&#8243;</span> &#8211; you must hack our noob filter machine and extract a file called <em>n00bSecret.txt</em> from the local filesystem. Once you have the key, you have 10 minutes to submit it into the control panel.</p>
<p style="text-align: justify;"><span style="color: #ff6600;">&#8220;Phase 2&#8243;</span> &#8211; The control panel will provide you with VPN files. Your VPN account will be automatically activated once you submit a correct &#8220;Phase 1&#8243; secret key. It will take 5 minutes for your account to get activated.</p>
<p style="text-align: justify;"><span style="color: #ff0000;">Due to the huge number of participants, we have currently enabled TWO noob filter machines for extra redundancy. Only the first 100 contestants to hack our noob filters will be allowed to proceed with Phase 2.</span></p>
<h3 style="text-align: justify;"><span style="color: #ff6600;">Tournament Info:</span></h3>
<ul>
<li>The tournament IRC Channel can be found at <span style="color: #ffff00;">#HSIYF on freenode.</span></li>
<li>Penetration of the boxes accounts for 60% of the score.</li>
<li>Documentation of the attacks accounts for 40% of the score.</li>
<li>The noob filter secret key is called n00bSecret.txt</li>
<li>Once key is found, you have 10 minutes to submit it in the <a title="Scoreboard" href="http://scoreboard.information-security-training.com/scoreboard/cp.php">control panel</a>.</li>
<li>The <a title="Scoreboard" href="http://scoreboard.information-security-training.com/scoreboard">scoreboard</a> will show the current status of the contestants.</li>
<li>Victim machines will be reverted every 30 minutes.</li>
<li>The vulnerabilities are &#8220;real world&#8221;, we wont be hiding passwords in javascript, images etc, just as network admins wouldn&#8217;t.</li>
</ul>
<h3><span style="color: #ff6600;">Tournament Rules:</span></h3>
<ul>
<li>Do not attack the scoreboard!</li>
<li>Do not attack any ips NOT listed below!</li>
<li>No DOS, ARP spoofing or defacing &#8211; do not spoil the challenge for others.</li>
<li>No disruptive attacks please &#8211; the aim is that everyone gets to enjoy the tournament.</li>
<li><span style="color: #ff0000;">Anyone found disregarding these rules will be disqualified and banned.</span></li>
</ul>
<h3><span style="color: #ff6600;">Tournament IPS and URLS:</span></h3>
<ul>
<li><span style="color: #ff0000;">Your attacks MUST BE CONFINED to the following IP&#8217;s / URL&#8217;s:</span></li>
<li>Noob filter 1 &#8211; <a title="Noob Filter 1" href="http://www1.noob-filter.com" target="_blank">http://www1.noob-filter.com</a> (67.23.72.4)</li>
<li>Noob filter 2 &#8211; <a title="Noob Filter 2" href="http://www2.noob-filter.com" target="_blank">http://www2.noob-filter.com</a> (67.23.72.5)</li>
<li><span style="color: #ff0000;">NO OTHER ROUTABLE MACHINES SHOULD BE ATTACKED.</span></li>
<li>No disruptive attacks please &#8211; the aim is that everyone gets to enjoy the tournament.</li>
<li>Anyone found disregarding these rules will be disqualified and banned.</li>
</ul>
<h3><span style="color: #ff6600;">Submitting your Documentation:</span></h3>
<p>Once you have completed the event, you have two options for document submission:</p>
<ul>
<li><span style="color: #ffff00;">EITHER :</span> A writeup on a blog, website, etc. We will need a link to the post, as well as your nick and tournament email.</li>
<li><span style="color: #ffff00;">OR :</span> Send us a PDF file describing your attack &#8211; we may publish these.</li>
<li>Ideally, try to organize your notes as a penetration test report &#8211; screenshots and explanations of your attacks are required.</li>
<li>Once the tournament is over, it will take us 48 hours to evaluate the documentation and announce the winner.</li>
</ul>
<h3><span style="color: #ff6600;">Hints and Help:</span></h3>
<ul>
<li>FTP Credentials are : devil / killthen00b</li>
<li>Internal VPN IP&#8217;s &#8211; 192.168.6.66/67/68 (all same) and 192.168.6.70/71/72 (all same).</li>
<li>Follow our <a title="Offsec Twitter" href="http://twitter.com/offsectraining/">TWITTER</a> feeds&#8230;</li>
<li>Try harder</li>
<li>Don&#8217;t forget the IRC channel.</li>
<li><span style="color: #ff0000;">Online bruteforce attacks will not get you far, avoid them.</span></li>
<li><span style="color: #ff0000;">Some machines have protection mechanisms installed. Making too much noise will activate them&#8230;5 minute cooling periods will be enforced!</span></li>
</ul>
<h3><span style="color: #ff6600;">Final Notes:</span></h3>
<p style="text-align: justify;"><span style="color: #ffff00;">Please play nice. We all want to have a good time and enjoy the tournament, and not have to deal with malicious attacks outside the scope of the challenges. Remember &#8211; all the vulnerabilities are &#8220;real world&#8221;, we don&#8217;t play games.<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/events/hacking-tournament/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Offensive Security Hacking Tournament &#8211; Updates</title>
		<link>http://www.information-security-training.com/events/offensive-security-hacking-tournament-updates/</link>
		<comments>http://www.information-security-training.com/events/offensive-security-hacking-tournament-updates/#comments</comments>
		<pubDate>Tue, 04 May 2010 15:26:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[EVENTS]]></category>

		<guid isPermaLink="false">http://www.information-security-training.com/?p=623</guid>
		<description><![CDATA[Hacking tournament updates: When Offensive Security asked the community if they wanted to hack something (legally), the response that came back was overwhelming.  Hundreds of penetration testers and information security specialists poured in from all over the world. And so begins &#8220;How strong is your Fu ?&#8221;.
The team at Offsec gathered into a dark room [...]]]></description>
			<content:encoded><![CDATA[<div id="_mcePaste" style="text-align: justify;"><a href="http://www.information-security-training.com/images/are-you-ready-2.png"><img class="alignright" title="Offensive Security Hacking Tournament" src="http://www.information-security-training.com/images/are-you-ready-2.png" alt="" width="264" height="142" /></a>Hacking tournament updates: When Offensive Security <a title="How Strong is your Fu" href="http://www.information-security-training.com/news/offensive-security-hacking-tournament/" target="_blank">asked the community if they wanted to hack something</a> (legally), the response that came back was overwhelming.  Hundreds of penetration testers and information security specialists poured in from all over the world. And so begins &#8220;How strong is your Fu ?&#8221;.</div>
<div style="text-align: justify;">The team at Offsec gathered into a dark room in cold and damp basement and after shocking each other with a car battery for a few hours, we began to develop some of the most evil machines we have ever built.  We have given birth to a hack challenge that will release the full fury of the Offsec Lab Masters upon the world. You have been warned.</div>
<div style="text-align: justify;">With over 1000 registrations, we really didn&#8217;t want to deny anyone the <span style="text-decoration: line-through;">pain</span> pleasure of our challenge. We tripled up our lab space, and changed our concepts so that all registrants would be able to participate.</div>
<h3 style="text-align: justify;"><span style="color: #ff6600;"><strong>What to Expect:</strong></span></h3>
<ul>
<li style="text-align: justify;"><span style="color: #ff6600;">The challenge will be built of two Phases</span>, appropriately called &#8220;Phase 1&#8243; and &#8220;Phase 2&#8243;. Phase one is also humorously called &#8220;The noob filter&#8221;, as only the first 100 people who hack their way past this machine will pass on to &#8220;Phase 2&#8243;. Please do not be offended by the choice of machine names, it&#8217;s all done in humor. Once &#8220;Phase 1&#8243; is hacked by an attendee, they will find instructions on how to proceed to &#8220;Phase 2&#8243;.</li>
<li style="text-align: justify;">&#8220;<span style="color: #ff6600;">Phase 2&#8243; will involve VPN access to an internal lab</span>, with several additional machines which are trembling with anticipation for the <span style="text-decoration: line-through;">taunting session</span> hacking tournament.</li>
<li style="text-align: justify;"><span style="color: #ff6600;">All registered attendees will get an email on the 8th of May</span>, around 14:00 GMT (that means around 10am EST) with further instructions, attack adresses, etc. We have around 120 people who have not verified their registration &#8211; those will not be included in the list. If you did not get a confirmation email, re-register, or contact Offsec Staff (figure out how).</li>
</ul>
<p style="text-align: justify;">The Hacking tournament machines will be implemented in our <a title="Penetration Testing Training with BackTrack" href="http://www.offensive-security.com/online-information-security-training/penetration-testing-backtrack/">PWB</a> labs once the tournament is over. As we refresh our lab machines every so often&#8230; perhaps this could turn into a tradition ? <span style="color: #ff0000;">We are really looking forward to the hacking tournament, with some really slick victim machines set up&#8230;. we will be waiting for your pings.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.information-security-training.com/events/offensive-security-hacking-tournament-updates/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
