<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://fixme.ch/w/index.php?action=history&amp;feed=atom&amp;title=Fixme.ch%3AOldWiki%2FRwthCTF_2011</id>
		<title>Fixme.ch:OldWiki/RwthCTF 2011 - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://fixme.ch/w/index.php?action=history&amp;feed=atom&amp;title=Fixme.ch%3AOldWiki%2FRwthCTF_2011"/>
		<link rel="alternate" type="text/html" href="http://fixme.ch/w/index.php?title=Fixme.ch:OldWiki/RwthCTF_2011&amp;action=history"/>
		<updated>2026-04-17T02:16:14Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.25.1</generator>

	<entry>
		<id>http://fixme.ch/w/index.php?title=Fixme.ch:OldWiki/RwthCTF_2011&amp;diff=14055&amp;oldid=prev</id>
		<title>Rorist: 1 revision imported</title>
		<link rel="alternate" type="text/html" href="http://fixme.ch/w/index.php?title=Fixme.ch:OldWiki/RwthCTF_2011&amp;diff=14055&amp;oldid=prev"/>
				<updated>2019-03-06T20:36:44Z</updated>
		
		<summary type="html">&lt;p&gt;1 revision imported&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='1' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='1' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:36, 6 March 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan='2' style='text-align: center;'&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Rorist</name></author>	</entry>

	<entry>
		<id>http://fixme.ch/w/index.php?title=Fixme.ch:OldWiki/RwthCTF_2011&amp;diff=14054&amp;oldid=prev</id>
		<title>62.220.137.2 at 12:15, 13 October 2011</title>
		<link rel="alternate" type="text/html" href="http://fixme.ch/w/index.php?title=Fixme.ch:OldWiki/RwthCTF_2011&amp;diff=14054&amp;oldid=prev"/>
				<updated>2011-10-13T12:15:05Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= Quick links =&lt;br /&gt;
&lt;br /&gt;
* [https://grid.nimag.net/uri/URI%3ADIR2-RO%3Apn4ojukzl5wbr5qw7fumxzrlie%3Aobmcas6ttnjysvyahijofo2cumdsripjhkmqfczjxek2mvd3kghq/ Fichiers (network dumps, vm images, etc.)]&lt;br /&gt;
* [http://10.11.0.1/#scoreboard Scoreboard]&lt;br /&gt;
* [http://10.11.20.51/zabbix/index.php Monitoring] admin/zabbix&lt;br /&gt;
* [[Game]]&lt;br /&gt;
* [[Challenges]]&lt;br /&gt;
* Secret: shohwuinikeiquop&lt;br /&gt;
* Flag regex: &amp;lt;pre&amp;gt;^[a-zA-Z0-9]{40}$&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= SSH Access =&lt;br /&gt;
&lt;br /&gt;
Public key:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC5twrX47WdsuPX8BohNmuInE3Vjbd9XQ05gLMCjDaFaZDgt7B4BpQNfyGlvlCq3upPOwmpvFkH9+i7jSb3NCngN358OORWAuKm3rwLh0r1N/zL/uhz3Dzlpv1IFkm3Iev+J1eV1w4wfKhxvw2RyqL6t4csfowYlntpif5CCQ6wZqzJd+xFeJcTDlUHi9eVD8ew8qh4Wa2fZ1J4AdoKiYsVxHgVu2CzHGVKYSr217WuAiEg+P2guT/E99ZB4nRTWv8TNf4925BzsImvswNTnQjgh7h+q+zru4DncZn5EKlRJP/npTBcoLD274rLpehDdiBBKsIGNrwqYxWIi982ilPD FIXME@rwthCTF2011&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Ask info@fixme.ch for the private key!'''&lt;br /&gt;
&lt;br /&gt;
= Shared Git Repository =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
git clone fixme@guest1.fixme.ch:/home/fixme/rwthctf2011/repo/ rwthCTF-2011&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Fancy tools, mass exploitation!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ scoreboard.py targets | foreach.py attack1.py | upload-flags.py&lt;br /&gt;
Hello Team FIXME! You may now submit flags, one per line.&lt;br /&gt;
66c69cb0354079a1ad26e405851bc13c70964d51&lt;br /&gt;
Unknown flag.&lt;br /&gt;
5b713c95c31555bb76f8e4795e8a726c289918ce&lt;br /&gt;
Unknown flag.&lt;br /&gt;
[...]&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= SMB Share =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
smb://fixme@guest1.fixme.ch/media/rwthCTF-2011&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
= First Contact =&lt;br /&gt;
&lt;br /&gt;
'''Email'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-color: #eee; padding:3px; border: 1px dotted black&amp;quot;&amp;gt;&lt;br /&gt;
Hi rwthCTF Teams,&lt;br /&gt;
&lt;br /&gt;
with this message, the first ever rwthCTF is officially in the &amp;quot;team-preparation&amp;quot; phase. Attached to this mail you can find the first instructional README.txt file, a rough diagram of our network setup and a second document (codewars.txt) that serves as a small appetizer for the upcoming challenges in the CTF. The appetizer (codewars documentation) only describes a small part of the CTF event - we will have lots of programming languages and skill areas covered. Also the scripts mentioned in the document will only be made available when the competition starts.&lt;br /&gt;
&lt;br /&gt;
Additionally we prepared a &amp;quot;test-vulnbox&amp;quot; that can be downloaded from the link below. This is _NOT_ the final vulnbox image. Please refer to the README for further pointers. You will need this once VPN credentials are released - probably on next Monday (again see README).&lt;br /&gt;
&lt;br /&gt;
This E-Mail is signed with a PGP key and sent in PGP/MIME. Please download the corresponding public key from http://ctf.itsec.rwth-aachen.de/ and verify the signature. All further mail communication from rwthCTF organizers will be signed with this key as well.&lt;br /&gt;
&lt;br /&gt;
Cheers,&lt;br /&gt;
&lt;br /&gt;
rwthCTF Orga&lt;br /&gt;
&lt;br /&gt;
Test-Vulnbox: xxxxxxx&lt;br /&gt;
&lt;br /&gt;
GPG-symmetric-passphrase: xxxxxxx&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Attachments: ''' [[File:README.txt]] [[File:codewars.txt]]&lt;br /&gt;
&lt;br /&gt;
[[File:network.png|450px]]&lt;br /&gt;
&lt;br /&gt;
= VPN Credentials =&lt;br /&gt;
&lt;br /&gt;
'''Email'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-color: #eee; padding:3px; border: 1px dotted black&amp;quot;&amp;gt;&lt;br /&gt;
Hi rwthCTF Teams,&lt;br /&gt;
&lt;br /&gt;
with this mail you get your VPN credentials. This includes the openvpn config&lt;br /&gt;
file (client.conf), your team certificate (teamX.cert) and your private key&lt;br /&gt;
(teamX.key). Also needed by OpenVPN and attached to this mail are the CA&lt;br /&gt;
certificate &amp;quot;rwthctfca.pem&amp;quot; and a TLS shared key &amp;quot;ta.key&amp;quot;. These credentials can&lt;br /&gt;
only be used from _ONE_ machine at a time.&lt;br /&gt;
&lt;br /&gt;
The X in the files you receive is your team ID. This also specifies your IP&lt;br /&gt;
subnet 10.11.X.0/24! Please refer to the earlier README.txt for further details.&lt;br /&gt;
&lt;br /&gt;
Please connect to the VPN, set your IP addresses and bring up your routing. Also&lt;br /&gt;
start the Test Vulnbox and set it to 10.11.X.2.&lt;br /&gt;
&lt;br /&gt;
You can view a preliminary scoreboard at http://10.11.0.1/ During the CTF we&lt;br /&gt;
allow flag submission at 10.11.0.1 port 1/tcp. This should already be online for&lt;br /&gt;
testing purposes, but you can not score any points before the CTF starts on&lt;br /&gt;
September 30th. The rest of the network is pretty locked down at the moment -&lt;br /&gt;
you may ICMP, though.&lt;br /&gt;
&lt;br /&gt;
Any further questions should be asked via E-Mail or the #rwthctf IRC channel on&lt;br /&gt;
freenode.&lt;br /&gt;
&lt;br /&gt;
One last thing: each team was assigned a unique secret passphrase (secret.txt)&lt;br /&gt;
that is needed for certain critical actions during the competition. Keep it&lt;br /&gt;
safe!&lt;br /&gt;
&lt;br /&gt;
Cheers,&lt;br /&gt;
-rwthCTF Orga&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Thanks =&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-color: #eee; padding:3px; border: 1px dotted black&amp;quot;&amp;gt;&lt;br /&gt;
Hi rwthCTF Teams,&lt;br /&gt;
&lt;br /&gt;
thank you for participating in the rwthCTF 2011 competition. Hopefully we will meet again at another event or next year at rwthCTF.&lt;br /&gt;
&lt;br /&gt;
We updated the website with some pictures taken during the CTF and some results. Give it a visit at http://ctf.itsec.rwth-aachen.de/&lt;br /&gt;
&lt;br /&gt;
Thanks again,&lt;br /&gt;
-rwthCTF Orga&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Network =&lt;br /&gt;
&lt;br /&gt;
* [[File:network-setup.pdf]]&lt;br /&gt;
* labo.ctrlaltdel.ch: Virtual machine host&lt;br /&gt;
* rwthctf.fixme.ch: OpenVPN router&lt;br /&gt;
&lt;br /&gt;
'''10.11.20.0/25 DMZ'''&lt;br /&gt;
* 10.11.20.1 OpenVPN router&lt;br /&gt;
* 10.11.20.2 Vulnbox&lt;br /&gt;
* 10.11.20.3 Test vulnbox (dès le début de la compétition)&lt;br /&gt;
* 10.11.20.50 ructfe2010 vulnbox (testing purpose)&lt;br /&gt;
* 10.11.20.51 Monitoring&lt;br /&gt;
'''10.11.20.128/25 VPN clients'''&lt;br /&gt;
* 10.11.20.129 OpenVPN router&lt;br /&gt;
&lt;br /&gt;
Une capture réseau (tcpdump) tourne en permanence et sauve le trafic à destination de la vulnbox depuis le réseau du concours. Un nouveau fichier est créé chaque heure (attention aux sessions TCP coupées).&lt;br /&gt;
&lt;br /&gt;
=== Tcpdump ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ssh root@rwthctf.fixme.ch&lt;br /&gt;
root@openvpn:~# ls /srv/network-dumps/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Snort ===&lt;br /&gt;
&lt;br /&gt;
How to update the Snort IPS rules?&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
ssh root@rwthctf.fixme.ch&lt;br /&gt;
root@openvpn:~# vi /usr/local/etc/snort/rules/local.rules&lt;br /&gt;
root@openvpn:~# sv restart snort&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Orga Network ==&lt;br /&gt;
&lt;br /&gt;
* 10.11.0.1 Scoreboard + Flag submission&lt;br /&gt;
* 10.11.199.1 Vidéo surveillance?&lt;br /&gt;
&lt;br /&gt;
== Config OpenVPN ==&lt;br /&gt;
&lt;br /&gt;
* Créer un compte utilisateur après vous être connecté sur root@rwthctf.fixme.ch&lt;br /&gt;
* Créer les deux fichiers suivants&lt;br /&gt;
* ''$ openvpn openvpn.conf'' et entrer votre nom d'utilisateur/mot de passe&lt;br /&gt;
&lt;br /&gt;
'''openvpn.conf'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
client&lt;br /&gt;
remote rwthctf.fixme.ch&lt;br /&gt;
ca ./ca.pem&lt;br /&gt;
auth-user-pass&lt;br /&gt;
dev tun&lt;br /&gt;
proto tcp&lt;br /&gt;
nobind&lt;br /&gt;
persist-key&lt;br /&gt;
persist-tun&lt;br /&gt;
comp-lzo&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ca.pem'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
-----BEGIN CERTIFICATE-----&lt;br /&gt;
MIIFqTCCA5GgAwIBAgIJAOSjXeaKBcRpMA0GCSqGSIb3DQEBBQUAMB4xCzAJBgNV&lt;br /&gt;
BAYTAkNIMQ8wDQYDVQQDFAZNb25fQ0EwHhcNMTEwOTI0MTY1OTQ2WhcNMjEwOTIx&lt;br /&gt;
MTY1OTQ2WjAeMQswCQYDVQQGEwJDSDEPMA0GA1UEAxQGTW9uX0NBMIICIjANBgkq&lt;br /&gt;
hkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAqvKdC+tqLLB1Yfx8gcP2enLtfLdmVHHm&lt;br /&gt;
vnRBGQ9OpgBNZ1F5YHej7Z5y8Hnf3FuSzpYWJXprTxYFW6yK6G4FVxMF8WsyGPHz&lt;br /&gt;
CvYoBBUAAXt5D9fh5LQAa08cCtIzIGXw6NsVnfEwteqkzXa9eT8y8er81Da8FkLQ&lt;br /&gt;
fbnpTAwa03/eUds8JXLJEJ4+b2vV2Lh8+h1++3snuKpbGC1yEcUah0TT2SSI/a5Z&lt;br /&gt;
aQTOQ7A9oQ7+HbicFTj/p+/F+GwtnyJ8rNUJ976BGpdyna+IYOgW9BRFVWXjDkaE&lt;br /&gt;
iV3H7ms69WMNj7KQiavHqwkhxFsFLKSW5uUSKs5foRBosU3V5eKIS36lgMpX+jiu&lt;br /&gt;
9lAZfDebTlR1GLyuu6R9h4P1XJCN+ARRraza+fXgvOpNs5nK2H5eIdn2pc+I0EC0&lt;br /&gt;
hRgl0FkNSgUHg0UBLL6rcemHWMe16RbERJm3rWQZrxleT0DVPRq+CPcYdcfPTb91&lt;br /&gt;
TM7a/0z1d1uIJ7j/b1P81pLzBi8iYo0mUYV4b/thsHiHArmD2oGlUMVX/XIxfyvY&lt;br /&gt;
hxKtJ5TjouVj/4dSToUInYIiKoRYETlQ98glHIKVcSe3wmfoxBmDT9/DU/n1DRba&lt;br /&gt;
+5R7l4O1XNG7dWswgQeo71iDdmm5NfGHO2dNaMVjBE6sRKOvjFTFajBiCnThaWjI&lt;br /&gt;
MCHqBnU7fmcCAwEAAaOB6TCB5jAdBgNVHQ4EFgQU1LcU8uQlperS2ANo8aW+CiMG&lt;br /&gt;
rlYwTgYDVR0jBEcwRYAU1LcU8uQlperS2ANo8aW+CiMGrlahIqQgMB4xCzAJBgNV&lt;br /&gt;
BAYTAkNIMQ8wDQYDVQQDFAZNb25fQ0GCCQDko13migXEaTAPBgNVHRMBAf8EBTAD&lt;br /&gt;
AQH/MBEGCWCGSAGG+EIBAQQEAwIBBjAJBgNVHRIEAjAAMCsGCWCGSAGG+EIBDQQe&lt;br /&gt;
FhxUaW55Q0EgR2VuZXJhdGVkIENlcnRpZmljYXRlMAkGA1UdEQQCMAAwDgYDVR0P&lt;br /&gt;
AQH/BAQDAgEGMA0GCSqGSIb3DQEBBQUAA4ICAQBpVrrhHjcWxoHZ/3WJ61r5WvUC&lt;br /&gt;
H3+op0yzZkG/z498Gv4oUSErD5WfhG2K9+lV8VhRx2JSXCKv1SskHlJuPKDnWTdZ&lt;br /&gt;
bAUERSwZT/LvLYwRfH+8pWxSBMQRvvHEIzkrrRBNDQl4291/901o7nu41UFl6nBw&lt;br /&gt;
819+F+lWB+fRFm0YGIR4zzhvx3bFMGWCM3475l4WyRruYbe+soHs+g4+SUFYTK59&lt;br /&gt;
4PSjVrNvR8wMKQJByez0TaffGAxjeXde74kWPBPmhwqjq78fZ8wYAjVdn2ae/xjA&lt;br /&gt;
wIf+UvvntOkLwOiQWeCy2LMX3JbLvIUeirqtBeTDfgX80kcr6NHu6tDtiwY+V1/O&lt;br /&gt;
149pewBHebrMnJl90CayqDyF34RfZI/t2Z50LdLwPw2nTFgl1IO0Cou9qmfKW4gB&lt;br /&gt;
RNHtfGveYaR4wL6pF0ruiKGlwnh6cHFtS4a32G3HrQ7WKjk9FVGiDJvo93TBfUMl&lt;br /&gt;
mDjIqpq3wCCJynxGyVmQVWH65/3gtnduCDfKrmbrL2DYUJeqBWW3cyPlSxEO/ei7&lt;br /&gt;
3Jx3qM5Jzngh9YRSUYBh5+3XB+4smsjRqpNtC3RdD074qxKhM5Acb0YcGmLJfgw4&lt;br /&gt;
3/d2JXQFvPJv8bKZ/WsK5VUeTGgqvi/8j2BqZjf6TMXKQRVmJ8tvvW/SBSqPZlCJ&lt;br /&gt;
kAslCDHslFeD6QYwMA==&lt;br /&gt;
-----END CERTIFICATE-----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>62.220.137.2</name></author>	</entry>

	</feed>