Differences

This shows you the differences between two versions of the page.

Link to this comparison view

— isc:labs:test-lab01 [2026/10/02 21:44] (current)
mihai.chiroiu created
Line 1: Line 1:
 +/* ~~SHOWSOLUTION~~ */
 +
 +====== Lab 01 - Security Foundations & The CIA Triad ======
 +
 +===== The Pitch: Theory Meets Practice =====
 +
 +Welcome to the Introduction to Cybersecurity (ISC) labs! 
 +
 +In Lecture 1, we discussed security at a high level: the **CIA Triad** (Confidentiality,​ Integrity, Availability),​ **Attack Surfaces**, **Threat Actors**, and **Security Policies**. But how do we apply these theoretical concepts in practice? ​
 +
 +In the real world, defenders and attackers do not rely on clicking buttons in graphical interfaces; they rely on automation and a deep understanding of operating systems. Throughout this course, we will use three core pillars to bridge the gap between theory and practice:
 +  * **Bash & The Command Line:** The universal language of infrastructure. You will use Bash to rapidly audit systems, verify data **Integrity**,​ and parse logs for **Indicators of Compromise (IoCs)**.
 +  * **Python Scripting:​** Attackers use automation to map the **Attack Surface** at scale. You will use Python to write custom network fuzzers, interact with remote services, and automate attacks.
 +  * **Codifications (Encodings):​** Data is often transmitted in various formats (Base64, Hexadecimal). It is crucial to understand that **Encoding is NOT Encryption**. Encoding provides zero **Confidentiality**,​ but attackers constantly use it for **Evasion** (hiding malicious payloads from defenders).
 +
 +Every task in this lab is a direct application of the theoretical concepts discussed in Lecture 1.
 +
 +===== Objectives =====
 +  * See how the **CIA Triad** dictates the security posture of a system.
 +  * Understand the difference between obfuscation (codification) and actual Confidentiality.
 +  * Verify data **Integrity** using cryptographic baselines.
 +  * Analyze **Availability** compromises by hunting for IoCs in server logs.
 +  * Map an **Internal** and **External Attack Surface** using Bash and Python.
 +
 +===== Preparation =====
 +
 +You may use the UPB's OpenStack cloud to spawn a Virtual Machine to be used for this lab!
 +[[:​isc:​info:​virtualmachine|Read this guide]].
 +
 +{{page>:​isc:​rec&​nofooter&​noeditbutton}}
 +
 +Download the {{:​isc:​labs:​isc-lab01.zip|task archive}} for this section. Unzip it. Each exercise will have a corresponding folder.
 +
 +===== Part 1: Confidentiality & Evasion =====
 +
 +**Lecture Concept:** Confidentiality & Attacker Evasion.
 +Developers sometimes mistakenly use codifications (like Base64) to hide sensitive data, confusing obfuscation with cryptography. Alternatively,​ attackers encode their payloads to evade intrusion detection systems. ​
 +
 +==== 01. The Illusion of Security ====
 +  * **Context:​** We discovered a suspicious file (''​secret.txt''​) on a compromised server. The attacker tried to evade our defenses by encoding the payload multiple times.
 +  * **Task:** Using **Bash** pipelines or a **Python** script, decode the file to reveal the plaintext flag. You will need to identify the encodings (Base64, Hexadecimal) and reverse them layer by layer.
 +  * **Tools:** Bash: ''​cat'',​ ''​base64 -d'',​ ''​xxd -r -p''​. Python: ''​base64''​ module, ''​bytes.fromhex()''​.
 +
 +===== Part 2: Integrity & Indicators of Compromise =====
 +
 +**Lecture Concept:** Integrity, Baselines, and IoCs.
 +Integrity ensures data hasn't been maliciously modified. Defenders use cryptographic hashes to create a "​baseline"​ of a healthy system. If a file's hash changes, it serves as an **Indicator of Compromise (IoC)** pointing to a malware infection.
 +
 +==== 02. The Tampered Asset ====
 +  * **Context:​** We suspect an Advanced Persistent Threat (APT) breached our server and planted a backdoor in one of our system binaries.
 +  * **Task:** Inside the ''​02-integrity/''​ folder, there are 50 executables. You are provided with a ''​checksums.txt''​ file containing the original, trusted SHA-256 hashes of these files (the baseline). Use **Bash** to automatically check the hashes of all files against the baseline and find the compromised (tampered) file. The flag is written inside the tampered file!
 +  * **Tools:** Look at the ''​man''​ page for ''​sha256sum'',​ specifically the ''​-c''​ (check) flag.
 +  * **Hint:** ''​sha256sum -c checksums.txt | grep FAILED''​
 +
 +===== Part 3: Availability & Auditing =====
 +
 +**Lecture Concept:** Availability,​ Denial of Service (DoS), and Auditing.
 +To protect Availability,​ we must monitor (audit) user events. When a DoS attack occurs, the logs hold the key to identifying the attacker'​s TTPs and blocking them.
 +
 +==== 03. Hunting the Threat Actor ====
 +  * **Context:​** Our web server crashed last night. We suspect a resource exhaustion attack (DoS).
 +  * **Task:** You are given the ''​access.log''​ file of the web server. Use **Bash** text-processing tools to act as a SOC analyst: parse the logs and find the **Indicator of Attack (IoA)**—the IP address that sent an unnaturally high amount of requests. The flag format is ''​ISC{IP_ADDRESS}''​.
 +  * **Tools:** ''​awk'',​ ''​sort'',​ ''​uniq''​.
 +  * **Hint:** Extract the first column (IPs) using ''​awk '​{print $1}' access.log''​. Pipe (''​|''​) that into ''​sort'',​ then ''​uniq -c''​ to count duplicates, and finally ''​sort -nr''​ to find the biggest offender.
 +
 +===== Part 4: Attack Surface & Least Privilege =====
 +
 +**Lecture Concept:** Internal Attack Surface & Least Privilege.
 +Complex systems are difficult to secure. Sometimes the biggest threat isn't external, but an internal mistake where an administrator violates the principle of Least Privilege.
 +
 +==== 04. The Internal Attack Surface ====
 +  * **Context:​** You have gained a low-privileged foothold on a legacy Linux machine. System administrators often leave sensitive **assets** scattered in deep directory structures with overly permissive read access.
 +  * **Task:** Inside the ''​04-internal-surface/''​ folder is a deeply nested directory tree simulating a Linux filesystem. Use **Bash** to recursively search through all the files and find the forgotten asset (a file containing the string "​ISC{"​). ​
 +  * **Tools:** ''​grep''​.
 +  * **Hint:** Use ''​grep -r "​ISC{"​ .''​ to search recursively.
 +
 +===== Part 5: Python Automation =====
 +
 +**Lecture Concept:** External Attack Surface & Automated Attackers (Script Kiddies).
 +Attackers don't map external attack surfaces by clicking links in a browser; they automate the process to find forgotten administrative panels, backups, or API endpoints.
 +
 +==== 05. Mapping the External Attack Surface (Web Fuzzer) ====
 +  * **Preparation:​** Start this task by opening a specific docker container on your VM: 
 +<code bash>
 +docker run -d -p 8080:80 ghcr.io/​cs-pub-ro/​isc-lab-intro-web
 +</​code>​
 +  * **Context:​** The target web server is now running on ''​http://​localhost:​8080''​. ​
 +  * **Task:** You have a wordlist (''​paths.txt''​). Write a **Python script** that automates HTTP GET requests to the server for every path in the wordlist. Find the hidden endpoint that actually exists (returns an HTTP 200 OK status code instead of a 404 Not Found) to retrieve the hidden flag!
 +  * **Tools:** Use the [[https://​requests.readthedocs.io/​en/​latest/​|Python requests library]]. Use a ''​for''​ loop to read the file, and check ''​response.status_code''​.
 +
 +===== Feedback =====
 +
 +{{page>:​isc:​lab-feedback&​nofooter&​noeditbutton}}
  
isc/labs/test-lab01.txt · Last modified: 2026/10/02 21:44 by mihai.chiroiu
CC Attribution-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0