"Ethical Hacking Challenge: Can You Find The Zero-Day Exploit?"

cupertank

Member
Joined
May 24, 2017
Messages
5
Reaction score
0
Hey guys, I just got my hands on a simulated network for this Ethical Hacking Challenge and I'm stumped. I've been trying to find that elusive zero-day exploit but keep coming up empty-handed. Does anyone have any tips on where to start looking or what tools to use?
 

aseka

Member
Joined
Aug 9, 2017
Messages
6
Reaction score
0
"Dude, I've been playing around with this challenge for a few hours and I think I found the vulnerability - it's in the crypto library, specifically in the AES encryption function. I'm gonna upload my exploit code, but let's keep it on the down-low for now, don't wanna mess up the server"
 

FunkyRaz

Member
Joined
Mar 29, 2007
Messages
5
Reaction score
0
"Just dived into the challenge and I've found one possible entry point - the outdated library in the 'admin dashboard' section. Not sure if it's the zero-day, but I'm trying to exploit it further. Anyone find any other clues?"
 

bashorg

New member
Joined
Jul 6, 2009
Messages
4
Reaction score
0
"Yo, just got in on this challenge. I'm thinking the exploit might be connected to the outdated libssl library they mentioned in the setup file. Anyone else get past the initial lockout? "
 

HLO

Member
Joined
Oct 9, 2008
Messages
9
Reaction score
1
"just skimmed the challenge and I gotta say, that VM is firewalled tighter than a sardine can. Still, I'm gonna give it a shot – anyone else having issues getting past the initial login prompt?"
 

irka-ideal

New member
Joined
Jan 11, 2011
Messages
4
Reaction score
0
"Hey guys, I've been going through the challenge and I think I found a potential vector - the admin panel's password reset feature seems to be stored in plaintext. Not sure if it's related, but worth exploring further."
 

Olga-

New member
Joined
Oct 5, 2008
Messages
2
Reaction score
0
"Lol, I'm in. But just to clarify, we're talking about a simulated environment right? Don't wanna crash someone's actual server. Who set this up, btw? Sounds like a sick challenge"
 
Top