{"id":121,"date":"2011-10-28T14:04:36","date_gmt":"2011-10-28T14:04:36","guid":{"rendered":"http:\/\/www.miamip0wnmachine.com\/?p=121"},"modified":"2013-04-30T16:27:25","modified_gmt":"2013-04-30T16:27:25","slug":"kommand-kontroll-ctf-at-hacker-halted-2011","status":"publish","type":"post","link":"https:\/\/www.kandkctf.com\/?p=121","title":{"rendered":"Kommand &#038;&#038; KonTroll CTF at Hacker Halted &#8211; Miami, 2011"},"content":{"rendered":"<p><a href=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/09\/HH-logo-v2011.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-79 aligncenter\" title=\"HH-logo-v2011\" alt=\"\" src=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/09\/HH-logo-v2011.png\" width=\"335\" height=\"76\" srcset=\"https:\/\/www.kandkctf.com\/wp-content\/uploads\/2011\/09\/HH-logo-v2011.png 335w, https:\/\/www.kandkctf.com\/wp-content\/uploads\/2011\/09\/HH-logo-v2011-300x68.png 300w\" sizes=\"auto, (max-width: 335px) 100vw, 335px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/08\/banner1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-40\" title=\"banner\" alt=\"\" src=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/08\/banner1.jpg\" width=\"468\" height=\"60\" srcset=\"https:\/\/www.kandkctf.com\/wp-content\/uploads\/2011\/08\/banner1.jpg 468w, https:\/\/www.kandkctf.com\/wp-content\/uploads\/2011\/08\/banner1-300x38.jpg 300w\" sizes=\"auto, (max-width: 468px) 100vw, 468px\" \/><\/a><\/p>\n<p>We had an awesome time at Hacker Halted 2011. We had some great players and pretty cool<a href=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/11\/aj.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-thumbnail wp-image-155\" title=\"aj\" alt=\"\" src=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/11\/aj-150x150.jpg\" width=\"150\" height=\"150\" \/><\/a><br \/>\npeople stopping by and checking it out.<\/p>\n<p>Thanks\u00a0 and congratulations to @dan_crowley and @jolly for winning the CTF and also winning at the Cyberlimpycs.<\/p>\n<p>Dan was p0wning targets LEFT\u00a0 and RIGHT. Awesome job!. Let&#8217;s take a look at the hardware related challenges we featured at this edition of Kommand &amp;&amp; KonTroll CTF<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-thumbnail wp-image-122 alignleft\" title=\"328627_2282337011173_1031256169_2506763_1566172966_o\" alt=\"\" src=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/328627_2282337011173_1031256169_2506763_1566172966_o-150x150.jpg\" width=\"150\" height=\"150\" \/>In this picture we have the 3 hardware related challenges.<\/p>\n<p>PrintMe Flag. The only way to win this flag was to first compromise the target VM at the ESXi then escalate privileges and finally print the flag.<\/p>\n<p>At the center there is an Arduino UNO\/Ethernet shield. This was pretty easy. It consisted of a HTTP parameter that had to be modified in order to turn ON \/OFF the LED in a certain sequence. Most players got this one pretty fast.<\/p>\n<p>Then the SheevaPlug server which could be by itself a single CTF. I used this one for Flash M0b CTF at DEFCON but back then this little wonder was running a FULLY functional C&amp;C with two Zombies which were XP SP2s. This time it was running an install of WP that had several vulnerable plugins and the flag was the MD5 hash found at password table. Also notice that there is an USB programmable LED display attached to it. The characters displayed were also modifiable but to do it player had to gain root and compile some code which is actually available on the internet.<\/p>\n<p>Most targets at Kommand &amp;&amp; KonTroll CTF have SEVERAL attack vectors as I try to give players with different backgrounds the opportunity to win it, be it a web app or network or binary type of background. Below are some pictures of the event. If you want us to be at your event or you organize these type of competitions and want us to partner up feel free to reach out to us at info@kommandkontrollctf.com . Thanks again to EC-Council and all the people at Hacker Halted 2011 that stopped by and played.\u00a0 And for the record no one has yet taken over the C&amp;C. Stay tuned for future dates&#8230;<\/p>\n<p><a href=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/340005_2282362051799_1031256169_2506778_194520688_o1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-127\" title=\"340005_2282362051799_1031256169_2506778_194520688_o\" alt=\"\" src=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/340005_2282362051799_1031256169_2506778_194520688_o1-150x150.jpg\" width=\"139\" height=\"117\" \/><\/a> <a href=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/328936_2282339771242_1031256169_2506765_952622871_o.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-126\" title=\"328936_2282339771242_1031256169_2506765_952622871_o\" alt=\"\" src=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/328936_2282339771242_1031256169_2506765_952622871_o-150x150.jpg\" width=\"136\" height=\"118\" \/><\/a><a href=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/326148_2282340771267_1031256169_2506767_990668068_o.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-124\" title=\"326148_2282340771267_1031256169_2506767_990668068_o\" alt=\"\" src=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/326148_2282340771267_1031256169_2506767_990668068_o-150x150.jpg\" width=\"150\" height=\"117\" \/><\/a><a href=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/328107_2282361011773_1031256169_2506777_691192236_o.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-123\" title=\"328107_2282361011773_1031256169_2506777_691192236_o\" alt=\"\" src=\"http:\/\/www.miamip0wnmachine.com\/wp-content\/uploads\/2011\/10\/328107_2282361011773_1031256169_2506777_691192236_o-150x150.jpg\" width=\"138\" height=\"115\" \/><\/a><\/p>\n<p>P.S: Most people said that the MUSIC was awesome. Well the music was basically hand picked Tech House\/Minimal\/Dubstep from MIA\/NYC\/London UNDERGROUND EDM scene which I am an avid follower of :)&#8230; No you won&#8217;t be hearing that music on the radio or TV anytime soon&#8230;..<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We had an awesome time at Hacker Halted 2011. We had some great players and pretty cool people stopping by and checking it out. Thanks\u00a0 and congratulations to @dan_crowley and @jolly for winning the CTF and also winning at the &hellip; <a href=\"https:\/\/www.kandkctf.com\/?p=121\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":true,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-121","post","type-post","status-publish","format-standard","hentry","category-main"],"_links":{"self":[{"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=\/wp\/v2\/posts\/121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=121"}],"version-history":[{"count":15,"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=\/wp\/v2\/posts\/121\/revisions"}],"predecessor-version":[{"id":131,"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=\/wp\/v2\/posts\/121\/revisions\/131"}],"wp:attachment":[{"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kandkctf.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}