The first cybersecurity project of 42 School - a series of challenges, be like CTF.
Snow-crash is an introductory cybersecurity project that teaches fundamental exploitation techniques through 10 mandatory and 5 bonus progressive levels. Each level requires finding and exploiting vulnerabilities to escalate privileges and retrieve flags.
snow_crash/
├── level00/ # File enumeration & Caesar cipher
├── level01/ # Password hash cracking
├── level02/ # Network traffic analysis
├── level03/ # PATH hijacking
├── level04/ # CGI RCE injection
├── level05/ # Cron job exploitation
├── level06/ # PHP preg_replace code injection
├── level07/ # Environment variable manipulation
├── level08/ # Symbolic link exploitation
├── level09/ # Character encoding/rotation cipher
├── level10/ # Race condition (TOCTOU)
├── level11/ # Command injection via Lua
├── level12/ # Perl script exploitation
├── level13/ # Binary patching/UID manipulation
└── level14/ # Final challege - getflag exploitation
Each level directory contains:
README.mdflag- the retrieved token
- Download the ISO
- Create VM in VirtualBox:
- Name: SnowCrash
- Type: Linux
- Version: Debian (64-bit)
- Memory: 1024 MB (minimum)
- Disc: Use existing virtual hard disk (the ISO)
- Network configuration:
- Settings -> Network -> Adapter 1
- Attached to: Briged Adapter
- Start the VM:
- Boot the VM and note the IP address displayed on login screen
ssh level00@<VM_IP> -p 4242
# Password: level00# Download from VM to local machine
scp -P 4242 levelXX@<VM_IP>:/path/on/vm /path/on/local/
# Upload from local machine to VM
scp -P 4242 /path/on/local/ levelXX@<VM_IP>:/path/on/vm- Download the ISO
- Launch the VM with port forwarding so you can SSH directly from your host:
qemu-system-x86_64 -cdrom SnowCrash.iso -m 1024 -boot d \
-netdev user,id=net0,hostfwd=tcp::4243-:4242 \
-device e1000,netdev=net0- SSH Connection using localhost and the forwarded port:
ssh level00@localhost -p 4243
# Password: level00# Download from VM to local machine
scp -P 4243 levelXX@localhost:/path/on/vm /path/on/local/
# Upload from local machine to VM
scp -P 4243 /path/on/local/ levelXX@localhost:/path/on/vmEach level has the same username and password initially:
- Username:
levelXX(e.g., level00, level01) - Password:
levelXX(same as username)
After retrieving a flag, use it to log into the next level:
su level00
# Enter the flag as password- John the Ripper - password cracking
- Wireshark - network analysis
- Ghidra - binary decompilation
- Tham Le (thi-le)
- Yulia Boktaeva (yuboktae)