Hacker Contest summer semester 2023: Sample solution of the challenge online

17. April 2023

In the 2023 summer semester, our "Hacker Contest" at Technical University (TU) Darmstadt and at Darmstadt University of Applied Sciences (h_da) will enter the next round. In the popular course Matthias Göhring, Head of usd HeroLab, Tobias Hamann, Senior Consultant IT Security at usd HeroLab, and Tim Wörner, Senior Consultant at usd HeroLab, give students concrete insights into IT security. For this purpose, the usd PentestLab provides a controlled environment in which students can attempt tools and attacks on IT systems and applications as a start. The objective is to identify and exploit vulnerabilities. A fixed component is a practical assignment in which the students independently examine open source software for vulnerabilities and report them to developers according to the usd Responsible Disclosure Process. Thus, the students contribute significantly to the security of open source software.

In order to qualify for participation in the Hacker Contest, the participants faced the Hacker Contest Challenge in the current semester as well.

The Challenge

In the current challenge, the goal was to analyze a fictitious insurance company for vulnerabilities that have a direct impact on the protection goals of information security. In order to close these vulnerabilities in a timely manner, the participants were asked to report understandable and easily reproducible vulnerability descriptions to the developers.

Experts from usd HeroLab have published a Write-up of the challenge for you in their LabNews. If you want to know what a Hacker Contest Challenge looks like, or what flags you might have missed: Click here for the sample solution Hacker Contest Challenge SoSe 2023.

Also interesting:

Andrea Tubach is the new CEO of usd AG

Andrea Tubach is the new CEO of usd AG

Yesterday, at usd's Annual General Meeting and the subsequent meeting of the new Supervisory Board, long-prepared personnel changes were unanimously approved and then celebrated with an atmosphere of deep friendship: Andrea Tubach takes over as CEO. The founder and...

Security Advisories on Vtiger

Security Advisories on Vtiger

The pentest professionals at usd HeroLab examined Vtiger Open Source Edition 8.2.0 during the execution of their pentests. Our analysts discovered two vulnerabilities in the Vtiger software that allow low-privileged authorized users to upload files and execute...

NIS-2 Draft Bill under Examination: Everything You Need to Know

NIS-2 Draft Bill under Examination: Everything You Need to Know

A few days ago, the AG KRITIS published the latest draft bill on the NIS-2 Implementation Law (NIS2UmsuCG) on its website. Which requirements could become relevant for you if the law is passed in this version? Our experts have analyzed the draft for you and summarized...

Categories

Categories