Vault7: CIA Hacking Tools Revealed
Navigation: » Latest version
12. Bonus: Capture The Flag
SECRET//NOFORN
Capture The Flag
('toc' missing)
Setup
On the share (\\FS-01\share\NewDeveloperExercises\CaptureTheFlags) there is a VMVirtual Machine titled "New Developer CTFCapture the Flag Windows 8.1 x64". Copy the VMVirtual Machine folder to your local machine. If VMWare asks, you copied it.
Submitting Answers
Text Here
Challenge 1: Survey
Take a survey of the CTFCapture the Flag VMVirtual Machine and output a file to a location where the watcher will notice it and validate it.
Challenge 2: File Collection
Collect all files that match a certain type from a certain location. Copy the files to a certain location (set event to signal you're done). Files will be validated.
Encryption and Compression
Encrypt Improve Dummy With The Following Key - (Use Secure Buffer) and output the encrypted file to a certain location
Payload Deployment
Kick off Dummy Payload using CreateProcess and LoadLibrary on a dll
Persistence
Create Sched Task as user, logoff and logon to get flag
Data Transfer
Execute Survey from part one, pipe it to me over a known named pipe
PSP Evasion
Known Bad Executable + Src. Known defeats. Verify it passes
Execution Vectors
Trojan - take winrar and trojan it, validate resources and application startup
Privilege Escalation
Describe Artillery UACUser Account Control Bypass, Have them write it to execute ImprovedDummy as Administrator.
Finishing Up
As we go on, we remember, all the time we...
SECRET//NOFORN