This shows you the differences between two versions of the page.
| — |
isc:labs:test-lab01 [2026/10/02 21:44] (current) mihai.chiroiu created |
||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | /* ~~SHOWSOLUTION~~ */ | ||
| + | |||
| + | ====== Lab 01 - Security Foundations & The CIA Triad ====== | ||
| + | |||
| + | ===== The Pitch: Theory Meets Practice ===== | ||
| + | |||
| + | Welcome to the Introduction to Cybersecurity (ISC) labs! | ||
| + | |||
| + | In Lecture 1, we discussed security at a high level: the **CIA Triad** (Confidentiality, Integrity, Availability), **Attack Surfaces**, **Threat Actors**, and **Security Policies**. But how do we apply these theoretical concepts in practice? | ||
| + | |||
| + | In the real world, defenders and attackers do not rely on clicking buttons in graphical interfaces; they rely on automation and a deep understanding of operating systems. Throughout this course, we will use three core pillars to bridge the gap between theory and practice: | ||
| + | * **Bash & The Command Line:** The universal language of infrastructure. You will use Bash to rapidly audit systems, verify data **Integrity**, and parse logs for **Indicators of Compromise (IoCs)**. | ||
| + | * **Python Scripting:** Attackers use automation to map the **Attack Surface** at scale. You will use Python to write custom network fuzzers, interact with remote services, and automate attacks. | ||
| + | * **Codifications (Encodings):** Data is often transmitted in various formats (Base64, Hexadecimal). It is crucial to understand that **Encoding is NOT Encryption**. Encoding provides zero **Confidentiality**, but attackers constantly use it for **Evasion** (hiding malicious payloads from defenders). | ||
| + | |||
| + | Every task in this lab is a direct application of the theoretical concepts discussed in Lecture 1. | ||
| + | |||
| + | ===== Objectives ===== | ||
| + | * See how the **CIA Triad** dictates the security posture of a system. | ||
| + | * Understand the difference between obfuscation (codification) and actual Confidentiality. | ||
| + | * Verify data **Integrity** using cryptographic baselines. | ||
| + | * Analyze **Availability** compromises by hunting for IoCs in server logs. | ||
| + | * Map an **Internal** and **External Attack Surface** using Bash and Python. | ||
| + | |||
| + | ===== Preparation ===== | ||
| + | |||
| + | You may use the UPB's OpenStack cloud to spawn a Virtual Machine to be used for this lab! | ||
| + | [[:isc:info:virtualmachine|Read this guide]]. | ||
| + | |||
| + | {{page>:isc:rec&nofooter&noeditbutton}} | ||
| + | |||
| + | Download the {{:isc:labs:isc-lab01.zip|task archive}} for this section. Unzip it. Each exercise will have a corresponding folder. | ||
| + | |||
| + | ===== Part 1: Confidentiality & Evasion ===== | ||
| + | |||
| + | **Lecture Concept:** Confidentiality & Attacker Evasion. | ||
| + | Developers sometimes mistakenly use codifications (like Base64) to hide sensitive data, confusing obfuscation with cryptography. Alternatively, attackers encode their payloads to evade intrusion detection systems. | ||
| + | |||
| + | ==== 01. The Illusion of Security ==== | ||
| + | * **Context:** We discovered a suspicious file (''secret.txt'') on a compromised server. The attacker tried to evade our defenses by encoding the payload multiple times. | ||
| + | * **Task:** Using **Bash** pipelines or a **Python** script, decode the file to reveal the plaintext flag. You will need to identify the encodings (Base64, Hexadecimal) and reverse them layer by layer. | ||
| + | * **Tools:** Bash: ''cat'', ''base64 -d'', ''xxd -r -p''. Python: ''base64'' module, ''bytes.fromhex()''. | ||
| + | |||
| + | ===== Part 2: Integrity & Indicators of Compromise ===== | ||
| + | |||
| + | **Lecture Concept:** Integrity, Baselines, and IoCs. | ||
| + | Integrity ensures data hasn't been maliciously modified. Defenders use cryptographic hashes to create a "baseline" of a healthy system. If a file's hash changes, it serves as an **Indicator of Compromise (IoC)** pointing to a malware infection. | ||
| + | |||
| + | ==== 02. The Tampered Asset ==== | ||
| + | * **Context:** We suspect an Advanced Persistent Threat (APT) breached our server and planted a backdoor in one of our system binaries. | ||
| + | * **Task:** Inside the ''02-integrity/'' folder, there are 50 executables. You are provided with a ''checksums.txt'' file containing the original, trusted SHA-256 hashes of these files (the baseline). Use **Bash** to automatically check the hashes of all files against the baseline and find the compromised (tampered) file. The flag is written inside the tampered file! | ||
| + | * **Tools:** Look at the ''man'' page for ''sha256sum'', specifically the ''-c'' (check) flag. | ||
| + | * **Hint:** ''sha256sum -c checksums.txt | grep FAILED'' | ||
| + | |||
| + | ===== Part 3: Availability & Auditing ===== | ||
| + | |||
| + | **Lecture Concept:** Availability, Denial of Service (DoS), and Auditing. | ||
| + | To protect Availability, we must monitor (audit) user events. When a DoS attack occurs, the logs hold the key to identifying the attacker's TTPs and blocking them. | ||
| + | |||
| + | ==== 03. Hunting the Threat Actor ==== | ||
| + | * **Context:** Our web server crashed last night. We suspect a resource exhaustion attack (DoS). | ||
| + | * **Task:** You are given the ''access.log'' file of the web server. Use **Bash** text-processing tools to act as a SOC analyst: parse the logs and find the **Indicator of Attack (IoA)**—the IP address that sent an unnaturally high amount of requests. The flag format is ''ISC{IP_ADDRESS}''. | ||
| + | * **Tools:** ''awk'', ''sort'', ''uniq''. | ||
| + | * **Hint:** Extract the first column (IPs) using ''awk '{print $1}' access.log''. Pipe (''|'') that into ''sort'', then ''uniq -c'' to count duplicates, and finally ''sort -nr'' to find the biggest offender. | ||
| + | |||
| + | ===== Part 4: Attack Surface & Least Privilege ===== | ||
| + | |||
| + | **Lecture Concept:** Internal Attack Surface & Least Privilege. | ||
| + | Complex systems are difficult to secure. Sometimes the biggest threat isn't external, but an internal mistake where an administrator violates the principle of Least Privilege. | ||
| + | |||
| + | ==== 04. The Internal Attack Surface ==== | ||
| + | * **Context:** You have gained a low-privileged foothold on a legacy Linux machine. System administrators often leave sensitive **assets** scattered in deep directory structures with overly permissive read access. | ||
| + | * **Task:** Inside the ''04-internal-surface/'' folder is a deeply nested directory tree simulating a Linux filesystem. Use **Bash** to recursively search through all the files and find the forgotten asset (a file containing the string "ISC{"). | ||
| + | * **Tools:** ''grep''. | ||
| + | * **Hint:** Use ''grep -r "ISC{" .'' to search recursively. | ||
| + | |||
| + | ===== Part 5: Python Automation ===== | ||
| + | |||
| + | **Lecture Concept:** External Attack Surface & Automated Attackers (Script Kiddies). | ||
| + | Attackers don't map external attack surfaces by clicking links in a browser; they automate the process to find forgotten administrative panels, backups, or API endpoints. | ||
| + | |||
| + | ==== 05. Mapping the External Attack Surface (Web Fuzzer) ==== | ||
| + | * **Preparation:** Start this task by opening a specific docker container on your VM: | ||
| + | <code bash> | ||
| + | docker run -d -p 8080:80 ghcr.io/cs-pub-ro/isc-lab-intro-web | ||
| + | </code> | ||
| + | * **Context:** The target web server is now running on ''http://localhost:8080''. | ||
| + | * **Task:** You have a wordlist (''paths.txt''). Write a **Python script** that automates HTTP GET requests to the server for every path in the wordlist. Find the hidden endpoint that actually exists (returns an HTTP 200 OK status code instead of a 404 Not Found) to retrieve the hidden flag! | ||
| + | * **Tools:** Use the [[https://requests.readthedocs.io/en/latest/|Python requests library]]. Use a ''for'' loop to read the file, and check ''response.status_code''. | ||
| + | |||
| + | ===== Feedback ===== | ||
| + | |||
| + | {{page>:isc:lab-feedback&nofooter&noeditbutton}} | ||