From 27C3 public wiki

Jump to: navigation, search

Tatort Internet

Contents

Schützt endlich unsere Rechner

Who are we?

A small group of dedicated programmers trying to bring some knowledge to the people about typical code vulnerabilities.

What this project is about

This project will be hosting a Wargame with levels of increasing difficultly to solve for the visitors of the 27C3. Each level will be vulnerable to one or more common bugs and you are to find these and use them to get access to the next level. So its basically about binary-leetness.

What is the motivation to solve the levels?

On the one hand you will either learn or practice valuable security skills and on the other hand the first 3 people to solve all levels will receive a price from us. Maybe a Club-Mate or alike.

How it works

You come to our table and request a login for our wargame system or just sent an E-Mail. With the login you are able to connect via ssh to <user>@ring0.de with port 2200

  • the levels are located below /srv/level*
  • you get a homedir in /tmp where you can build your stuff (gcc-3.4 and tcc are available to match the used compilers)

Step-Through

  1. You login and try to crack the binary of your next level
  2. When you cracked it you want to call a shell and run `next` in it which adds your achievement to the list
  3. The system is handled via group rights ergo you have to relogin to gain access to the next level

Where to find us

Our table is located in the hackcenter on the parquet.

Final Results

level1: pge,corny,hawkje,ah,blair,raim,cnu,usc level2: pge,corny,hawkje,ah,raim,cnu,usc level3: hawkje,corny,cnu,usc,raim level4: hawkje,usc,cnu level5: hawkje,cnu,usc

Thanks for playing and expect a new round next year.

Contact information

E-Mail: wargame​@ring0​.de [Do not copy&paste]

Ressources to help solving the levels

  • For personal training we suggest you try IO. If you can solve more then 15 of these levels this "Tartort Internet" will be a breeze.
Archived page - Impressum/Datenschutz