Lab 01 - Security Foundations & The CIA Triad

The Pitch: Theory Meets Practice

Welcome to the Introduction to Cybersecurity (ISC) labs!

In Lecture 1, we discussed security at a high level: the CIA Triad (Confidentiality, Integrity, Availability), Attack Surfaces, Threat Actors, and Security Policies. But how do we apply these theoretical concepts in practice?

In the real world, defenders and attackers do not rely on clicking buttons in graphical interfaces; they rely on automation and a deep understanding of operating systems. Throughout this course, we will use three core pillars to bridge the gap between theory and practice:

  • Bash & The Command Line: The universal language of infrastructure. You will use Bash to rapidly audit systems, verify data Integrity, and parse logs for Indicators of Compromise (IoCs).
  • Python Scripting: Attackers use automation to map the Attack Surface at scale. You will use Python to write custom network fuzzers, interact with remote services, and automate attacks.
  • Codifications (Encodings): Data is often transmitted in various formats (Base64, Hexadecimal). It is crucial to understand that Encoding is NOT Encryption. Encoding provides zero Confidentiality, but attackers constantly use it for Evasion (hiding malicious payloads from defenders).

Every task in this lab is a direct application of the theoretical concepts discussed in Lecture 1.

Objectives

  • See how the CIA Triad dictates the security posture of a system.
  • Understand the difference between obfuscation (codification) and actual Confidentiality.
  • Verify data Integrity using cryptographic baselines.
  • Analyze Availability compromises by hunting for IoCs in server logs.
  • Map an Internal and External Attack Surface using Bash and Python.

Preparation

You may use the UPB's OpenStack cloud to spawn a Virtual Machine to be used for this lab! Read this guide.

Download the task archive for this section. Unzip it. Each exercise will have a corresponding folder.

Part 1: Confidentiality & Evasion

Lecture Concept: Confidentiality & Attacker Evasion. Developers sometimes mistakenly use codifications (like Base64) to hide sensitive data, confusing obfuscation with cryptography. Alternatively, attackers encode their payloads to evade intrusion detection systems.

01. The Illusion of Security

  • Context: We discovered a suspicious file (secret.txt) on a compromised server. The attacker tried to evade our defenses by encoding the payload multiple times.
  • Task: Using Bash pipelines or a Python script, decode the file to reveal the plaintext flag. You will need to identify the encodings (Base64, Hexadecimal) and reverse them layer by layer.
  • Tools: Bash: cat, base64 -d, xxd -r -p. Python: base64 module, bytes.fromhex().

Part 2: Integrity & Indicators of Compromise

Lecture Concept: Integrity, Baselines, and IoCs. Integrity ensures data hasn't been maliciously modified. Defenders use cryptographic hashes to create a “baseline” of a healthy system. If a file's hash changes, it serves as an Indicator of Compromise (IoC) pointing to a malware infection.

02. The Tampered Asset

  • Context: We suspect an Advanced Persistent Threat (APT) breached our server and planted a backdoor in one of our system binaries.
  • Task: Inside the 02-integrity/ folder, there are 50 executables. You are provided with a checksums.txt file containing the original, trusted SHA-256 hashes of these files (the baseline). Use Bash to automatically check the hashes of all files against the baseline and find the compromised (tampered) file. The flag is written inside the tampered file!
  • Tools: Look at the man page for sha256sum, specifically the -c (check) flag.
  • Hint: sha256sum -c checksums.txt | grep FAILED

Part 3: Availability & Auditing

Lecture Concept: Availability, Denial of Service (DoS), and Auditing. To protect Availability, we must monitor (audit) user events. When a DoS attack occurs, the logs hold the key to identifying the attacker's TTPs and blocking them.

03. Hunting the Threat Actor

  • Context: Our web server crashed last night. We suspect a resource exhaustion attack (DoS).
  • Task: You are given the access.log file of the web server. Use Bash text-processing tools to act as a SOC analyst: parse the logs and find the Indicator of Attack (IoA)—the IP address that sent an unnaturally high amount of requests. The flag format is ISC{IP_ADDRESS}.
  • Tools: awk, sort, uniq.
  • Hint: Extract the first column (IPs) using awk '{print $1}' access.log. Pipe (|) that into sort, then uniq -c to count duplicates, and finally sort -nr to find the biggest offender.

Part 4: Attack Surface & Least Privilege

Lecture Concept: Internal Attack Surface & Least Privilege. Complex systems are difficult to secure. Sometimes the biggest threat isn't external, but an internal mistake where an administrator violates the principle of Least Privilege.

04. The Internal Attack Surface

  • Context: You have gained a low-privileged foothold on a legacy Linux machine. System administrators often leave sensitive assets scattered in deep directory structures with overly permissive read access.
  • Task: Inside the 04-internal-surface/ folder is a deeply nested directory tree simulating a Linux filesystem. Use Bash to recursively search through all the files and find the forgotten asset (a file containing the string “ISC{”).
  • Tools: grep.
  • Hint: Use grep -r “ISC{” . to search recursively.

Part 5: Python Automation

Lecture Concept: External Attack Surface & Automated Attackers (Script Kiddies). Attackers don't map external attack surfaces by clicking links in a browser; they automate the process to find forgotten administrative panels, backups, or API endpoints.

05. Mapping the External Attack Surface (Web Fuzzer)

  • Preparation: Start this task by opening a specific docker container on your VM:
docker run -d -p 8080:80 ghcr.io/cs-pub-ro/isc-lab-intro-web
  • Context: The target web server is now running on http://localhost:8080.
  • Task: You have a wordlist (paths.txt). Write a Python script that automates HTTP GET requests to the server for every path in the wordlist. Find the hidden endpoint that actually exists (returns an HTTP 200 OK status code instead of a 404 Not Found) to retrieve the hidden flag!
  • Tools: Use the Python requests library. Use a for loop to read the file, and check response.status_code.

Feedback

Please take a minute to fill in the feedback form for this lab.

isc/labs/test-lab01.txt · Last modified: 2026/10/02 21:44 by mihai.chiroiu
CC Attribution-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0