Security Basics mailing list archives

Re: hacking games


From: Fionnbharr <thouth () gmail com>
Date: Thu, 8 May 2008 19:46:20 +1000

Check out www.overthewire.org formally PullThePlug.

4 Different wargames -

Vortex
    By touring through the most common exploitable bugs, users of this
wargame are expected to have gained mastery in the basic fundamentals
of system exploitation.
Semtex
    Network-Based challenges, builds skills used in creating
server/client applications and challenges the user to figure out
problems with various network protocols.
Blacksun
    Blacksun is a wargame for learning more advanced exploitation
techniques against hardened hosts and environments.
Drifter
    Drifter is a new wargame, along the lines of vortex. It is
currently under development, if you would like to contribute levels /
ideas, please contact us. At this point in time, there is 5 levels.

Come check out our IRC server too at irc.overthewire.org, everyone is
usually very friendly.

2008/5/8 0x90 <secbasics () spam gagspace com>:

 Weird. I can't seem to find the original post to quote, I only see the
 responses. I will just guess what the original question was ;)

 Last year I wrote / posted my game to this list.

 http://hax.tor.hu/

 It isn't boring overcomplicated javascript, but neither smashing the stack
/
 defeating grsec type challenges.
 A little bit of everything that is basic.

 I hope it's useful information for at least one person.

 Best regards,
 0x90

 (list of challenges)
 Level 1. Make a nasa.gov URL display a text of my choice
 Level 2. debfKNH1AvtBo deGH9Aq./kiSY denjFRfA8kzL2
 Level 3. Recognize
 Level 4. IP address is 72.14.221.104. What contains 'art' that points to
it?
 Level 5. Password is the owl's name
 Level 6. Let's see you do some easy SQL ninjitsu
 Level 7. snifflog.txt - ngrep format
 Level 8. Password is on a picture: not available from anywhere
 Level 9. Elementary Maths
 Level 10. A poem
 Level 11. As simple as hashing a string
 Level 12. Ultra Turing
 Level 13. PHP with source - needs exploiting and/or o-o-t-b thinking
 Level 14. Recognize #2
 Level 15. download.com's uptime
 Level 16. root:hsmfs;g@10.0.0.5
 Level 17. Feed me!
 Level 18. Find all usernames
 Level 19. red+blue+green = ?
 Level 20. Recognize #3
 Level 21. Backdoor on a suspended domain
 Level 22. MS-Word
 Level 23. Too easy
 Level 24. Defense Intelligence Agency
 Level 25. BitNinja
 Level 26. PHP filemanager with source - needs more exploit
 Level 27. The photo doesn't load
 Level 28. telnet://hax.tor.hu:1800 - Google Word Game
 Level 29. Circumvent PHP filters for XSS
 Level 30. Create the given image using a number
 Level 31. Find all usernames v2.0
 Level 32. Exploit file2image.php
 Level 33. Defense Information Systems Agency - 199.57.1.130
 Level 34. Password is in the image
 Level 35. Follow the pattern
 Level 36. Root password needed
 Level 37. password = f(200)
 Level 38. Name the malware
 Level 39. China Science And Technology Network
 Level 40. I can has satellite?
 Level 41. Poem vs PHP
 Level 42. Criminal Minds FBI haxor scene
 Level 43. CNN's router
 Level 44. Blind SQL injection
 Level 45. Frogs n Toads
 Level 46. Seizure!!!!!!!
 Level 47. Backdoor is listening on host - find it
 Level 48. .htaccess editor vs basic auth
 Level 49. Forged DNS from the CIA
 Level 50. No info






Current thread: