1. Post #1
    Masquerade's Avatar
    July 2009
    62 Posts
    http://www.ustream.tv/channel/masquerade-demo

    Tonight's challenge for viewers, is RootThisBox. A Debian 5 box has been setup with core services installed. Your challenge, is to gain root access and place a file in the /root directory to mark your victory. Good luck. Feel free to use the uStream chat to help each other and post information/discoveries that may help you.

    Rules:

    No DoS/DDoS attacks
    Preventing others from participating in any way is forbidden
    These rules may change as needed

    Host: knox.masqueradenetworks.net


    Have fun!

    THIS CHALLENGE HAS NOW ENDED.

  2. Post #2
    Gold Member
    compwhizii's Avatar
    February 2007
    8,400 Posts
    I'm there.

  3. Post #3
    Gold Member
    its shortie's Avatar
    August 2008
    2,914 Posts
    I'm there.

  4. Post #4
    Masquerade's Avatar
    July 2009
    62 Posts
    Just finished the first run of the demo. I'll repeat for more people soon.

  5. Post #5
    VladH's Avatar
    July 2007
    171 Posts
    I'm also there.

    Edit:

    Disappointing, super old, patched exploits being demonstrated in VMs.

    Edit:

    cd /tmp/lolhack
    ./hack
    masquerade@192.168.2.150's password:

    "We're in!"

    Edit:



    Edit:

    When he was starting to do it right, VMWare failed. Yaay.

  6. Post #6
    Internet Detective (HBIED certified)
    leach139's Avatar
    August 2007
    6,813 Posts
    I'm there

  7. Post #7
    610925's Avatar
    June 2008
    633 Posts
    There

  8. Post #8
    Masquerade's Avatar
    July 2009
    62 Posts
    I'm also there.

    Edit:

    Disappointing, super old, patched exploits being demonstrated in VMs.

    Edit:

    cd /tmp/lolhack
    ./hack
    masquerade@192.168.2.150's password:

    "We're in!"

    Edit:



    Edit:

    When he was starting to do it right, VMWare failed. Yaay.
    VMWare failed me, yeah. And yep, demonstrating older exploits, so what? You'd prefer me to teach with current exploits...?

    Edited:

    Next stop, Vista.

  9. Post #9
    Gold Member
    wabash's Avatar
    June 2005
    451 Posts
    He doesn't want to try SQL Injection on .gov site, I was disappointed.

  10. Post #10
    Masquerade's Avatar
    July 2009
    62 Posts
    Looks like we're pretty much done for tonight.

    Ideas for future shows include different, perhaps more recent exploits (maybe some high profile but patched ones) and maybe a DEFCON style CTF tournament where I rig a box up with vulnerable services and people get points when they submit reports on each. Or perhaps just a root this box contest, first one to gain access wins. Opinions?

  11. Post #11
    Internet Detective (HBIED certified)
    leach139's Avatar
    August 2007
    6,813 Posts
    rootthisbox sounds fun

  12. Post #12
    nubcakez's Avatar
    January 2008
    2,586 Posts
    Release the script, damnit

  13. Post #13
    Masquerade's Avatar
    July 2009
    62 Posts
    I'll be doing tonight's show in a few hours.

    Edited:

    Can anyone recommend a platform/piece of software that will let me stream an 800x600 area of my desktop? I was using Procaster/LiveStream last night but some people complained it was a bit low res (this is because LiveStream was raping it down to 640x480, nothing I can do about that).

  14. Post #14
    toxicweirdo's Avatar
    October 2007
    820 Posts
    I'll be doing tonight's show in a few hours.

    Edited:

    Can anyone recommend a platform/piece of software that will let me stream an 800x600 area of my desktop? I was using Procaster/LiveStream last night but some people complained it was a bit low res (this is because LiveStream was raping it down to 640x480, nothing I can do about that).
    Theres options on procaster for hd, medium, low, high

  15. Post #15
    Masquerade's Avatar
    July 2009
    62 Posts
    Theres options on procaster for hd, medium, low, high
    You have to pay for the HD options though, free broadcasters only have one option. I'm currently testing using Flash Media Encoder.

    Edited:

    We've live: http://www.ustream.tv/channel/masquerade-demo

  16. Post #16
    Gold Member
    compwhizii's Avatar
    February 2007
    8,400 Posts
    Whoooo

  17. Post #17
    Baldr's Avatar
    July 2009
    3,891 Posts
    Interesting.... so when do you start?

  18. Post #18
    Masquerade's Avatar
    July 2009
    62 Posts
    I'll be starting once people have noticed the thread and a decent number joined. Not quite sure what I'll demo yet, open to suggestions. I can repeat last nights if there's demand for it.

  19. Post #19
    Gold Member
    slayer3032's Avatar
    November 2007
    2,393 Posts
    Argh I don't want to sign up to use chat.

    What's with the audio?

  20. Post #20
    a-k-t-w's Avatar
    March 2008
    2,677 Posts
    I'll be starting once people have noticed the thread and a decent number joined. Not quite sure what I'll demo yet, open to suggestions. I can repeat last nights if there's demand for it.
    I demand that you reshow me the xp one Now!

    I have to go soon :(

    Edit: nearly 10 viewers

    Edit2: Now can we start?

  21. Post #21
    Grayron's Avatar
    May 2009
    1,858 Posts
    i'm on.

    Edited:

    I don't want to sign up though :P

  22. Post #22
    Masquerade's Avatar
    July 2009
    62 Posts
    You can type /nick Name to change your name without signing up. Also, beginning soon.

  23. Post #23
    Baldr's Avatar
    July 2009
    3,891 Posts
    And it has begon!

  24. Post #24
    Masquerade's Avatar
    July 2009
    62 Posts
    Tonight's for viewers, is RootThisBox. A Debian 5 box has been setup with core services installed. Your challenge, is to gain root access and place a file in the /root directory to mark your victory. Good luck. Feel free to use the uStream chat to help each other and post information/discoveries that may help you.

    Rules:

    No DoS/DDoS attacks
    Preventing others from participating in any way is forbidden
    These rules may change as needed

    Edit: Box is located at knox.masqueradenetworks.net or 67.23.45.82. DNS A record has only just been added and will take a while to propagate.

    Edited:

    Edit2: FQDN is now resolving, have fun! :)

  25. Post #25
    Masquerade's Avatar
    July 2009
    62 Posts
    I'm off for the night, box will remain up until tomorrow. Tomorrow night's challenges will be cryptography based. Same time tomorrow, be there!

  26. Post #26
    Masquerade's Avatar
    July 2009
    62 Posts
    Nobody managed to root it. :(

    Anyway, can't do the live show tonight, but rest assured I'm working on challenges for you when I have time.