Please read the instructions before beginning!



Before you begin:



The structure of every flag is the following: whcd{[string]}, where [string] is either typed in l33t speek in honor of CTF challenges or contains some evidence related to the incident (e.g., timestamp, domain name). The exact flag format is displayed under the challenge descriptions (with examples).



  1. The credentials we have sent you:
    • URL, username and password to the Exam website (CTFd, this site);
    • IP addresses, username and password to the three VMs.
  2. You may extract payloads or artifacts from the machines to your environment for analysis with respect to the Exam rules.
  3. Solving the challenges do not require acquiring either full disk images or full memory dumps.
  4. There is no need for rebooting the machines to solve the challenges. Moreover, some volatile evidence may be lost forever if the systems restart. You can install tools you like without restarting the machines.
  5. The Documentation must be sent via email to the organizers by the end of the exam in PDF format. Organizers will reply with a confirmation.
  6. The two machines are:
    • doncike [10.0.0.5] - domain controller
    • rocco [10.0.0.4] - linux box


What we know so far:



Here we are at WHEX Marketing and PR Company. Thank you for coming to join our ongoing investigation. Here at the company, we're trying to keep up with the opportunities offered by AI in these new times. Management has agreed that we experiment with a local AI chatbot, which company employees have access to for now, just on a trial basis. Of course, this brings new challenges in terms of data protection, so we need to make sure that the infrastructure is well secured.

Unfortunately, preliminary investigations suggest that there are attackers present in the network and they have managed to gain access to the Linux server hosting the chatbot and the Windows Server running as Domain Controller.

We need to know the extent of the compromise, what techniques were used, what binaries were dropped, possibly what changes were made to the configuration, and how they ensured long-term access to our infrastructure. With your help, having this information will allow us to build effective defenses against future attacks. As a first step, save the logs to the desktop or your host machine, because external RDP or SSH brute-force attacks could overwrite the evidence.



Good luck and have fun!



A cool CTF platform from ctfd.io

Follow us on social media:

   


Click here to login and setup your CTF