Advent of Cyber 2024 Day 14: Even if we’re horribly mismanaged, there’ll be no sad faces on SOC-mas!

Lab link.

Questions

1. What is the name of the CA that has signed the Gift Scheduler certificate?

2. Look inside the POST requests in the HTTP history. What is the password for the snowballelf account?

3. Use the credentials for any of the elves to authenticate to the Gift Scheduler website. What is the flag shown on the elves’ scheduling page?

4. What is the password for Marta May Ware’s account?

5. Mayor Malware finally succeeded in his evil intent: with Marta May Ware’s username and password, he can finally access the administrative console for the Gift Scheduler. G-Day is cancelled!
What is the flag shown on the admin page?

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir