Welcome to the Introduction to Cybersecurity (ISC) labs!
In Lecture 1, we discussed security at a high level: the CIA Triad (Confidentiality, Integrity, Availability), Attack Surfaces, Threat Actors, and Security Policies. But how do we apply these theoretical concepts in practice?
In the real world, defenders and attackers do not rely on clicking buttons in graphical interfaces; they rely on automation and a deep understanding of operating systems. Throughout this course, we will use three core pillars to bridge the gap between theory and practice:
Every task in this lab is a direct application of the theoretical concepts discussed in Lecture 1.
You may use the UPB's OpenStack cloud to spawn a Virtual Machine to be used for this lab! Read this guide.
Download the task archive for this section. Unzip it. Each exercise will have a corresponding folder.
Lecture Concept: Confidentiality & Attacker Evasion. Developers sometimes mistakenly use codifications (like Base64) to hide sensitive data, confusing obfuscation with cryptography. Alternatively, attackers encode their payloads to evade intrusion detection systems.
secret.txt) on a compromised server. The attacker tried to evade our defenses by encoding the payload multiple times.cat, base64 -d, xxd -r -p. Python: base64 module, bytes.fromhex().Lecture Concept: Integrity, Baselines, and IoCs. Integrity ensures data hasn't been maliciously modified. Defenders use cryptographic hashes to create a “baseline” of a healthy system. If a file's hash changes, it serves as an Indicator of Compromise (IoC) pointing to a malware infection.
02-integrity/ folder, there are 50 executables. You are provided with a checksums.txt file containing the original, trusted SHA-256 hashes of these files (the baseline). Use Bash to automatically check the hashes of all files against the baseline and find the compromised (tampered) file. The flag is written inside the tampered file!man page for sha256sum, specifically the -c (check) flag.sha256sum -c checksums.txt | grep FAILEDLecture Concept: Availability, Denial of Service (DoS), and Auditing. To protect Availability, we must monitor (audit) user events. When a DoS attack occurs, the logs hold the key to identifying the attacker's TTPs and blocking them.
access.log file of the web server. Use Bash text-processing tools to act as a SOC analyst: parse the logs and find the Indicator of Attack (IoA)—the IP address that sent an unnaturally high amount of requests. The flag format is ISC{IP_ADDRESS}.awk, sort, uniq.awk '{print $1}' access.log. Pipe (|) that into sort, then uniq -c to count duplicates, and finally sort -nr to find the biggest offender.Lecture Concept: Internal Attack Surface & Least Privilege. Complex systems are difficult to secure. Sometimes the biggest threat isn't external, but an internal mistake where an administrator violates the principle of Least Privilege.
04-internal-surface/ folder is a deeply nested directory tree simulating a Linux filesystem. Use Bash to recursively search through all the files and find the forgotten asset (a file containing the string “ISC{”). grep.grep -r “ISC{” . to search recursively.Lecture Concept: External Attack Surface & Automated Attackers (Script Kiddies). Attackers don't map external attack surfaces by clicking links in a browser; they automate the process to find forgotten administrative panels, backups, or API endpoints.
docker run -d -p 8080:80 ghcr.io/cs-pub-ro/isc-lab-intro-web
http://localhost:8080. paths.txt). Write a Python script that automates HTTP GET requests to the server for every path in the wordlist. Find the hidden endpoint that actually exists (returns an HTTP 200 OK status code instead of a 404 Not Found) to retrieve the hidden flag!for loop to read the file, and check response.status_code.Please take a minute to fill in the feedback form for this lab.