Content improvements based on CA4S 2023
-
Webserver: sanitation/defanging of links and IPs in .bash_history DDoS on a website was launched during the competition because a student played around with a command from the history file. Proposed: Change IPs in the file to private ones. Change TLD in the URLs to .ex
. -
Client/Attacker: There was a complaint during the CA4S competition. A student used a freshly downloaded rockyou.txt
wordlist and couldn't solve one of the levels successfully. Proposed: Change an ssh key password to match the unalteredrockyou.txt
available online. Upload unaltered wordlist. Actually, we don't have to upload this wordlist as it should be a part of KALI Linux by default (/usr/share/wordlists
).
FYI @98724
Edited by Tomáš Sapák