Skip to content

Latest commit

 

History

25 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Snow-crash

The first cybersecurity project of 42 School - a series of challenges, be like CTF.

Table of contents

About

Snow-crash is an introductory cybersecurity project that teaches fundamental exploitation techniques through 10 mandatory and 5 bonus progressive levels. Each level requires finding and exploiting vulnerabilities to escalate privileges and retrieve flags.

Project structure

snow_crash/
├── level00/          # File enumeration & Caesar cipher
├── level01/          # Password hash cracking
├── level02/          # Network traffic analysis
├── level03/          # PATH hijacking
├── level04/          # CGI RCE injection
├── level05/          # Cron job exploitation
├── level06/          # PHP preg_replace code injection
├── level07/          # Environment variable manipulation
├── level08/          # Symbolic link exploitation
├── level09/          # Character encoding/rotation cipher
├── level10/          # Race condition (TOCTOU)
├── level11/          # Command injection via Lua
├── level12/          # Perl script exploitation
├── level13/          # Binary patching/UID manipulation
└── level14/          # Final challege - getflag exploitation

Each level directory contains:

  • README.md
  • flag - the retrieved token

Setup

Option 1: VirtualBox (Bridged Adapter)

  1. Download the ISO
  2. Create VM in VirtualBox:
    • Name: SnowCrash
    • Type: Linux
    • Version: Debian (64-bit)
    • Memory: 1024 MB (minimum)
    • Disc: Use existing virtual hard disk (the ISO)
  3. Network configuration:
    • Settings -> Network -> Adapter 1
    • Attached to: Briged Adapter
  4. Start the VM:
    • Boot the VM and note the IP address displayed on login screen

Connecting to the VM

SSH Connection

ssh level00@<VM_IP> -p 4242
# Password: level00

File transfer (SCP)

# Download from VM to local machine
scp -P 4242 levelXX@<VM_IP>:/path/on/vm /path/on/local/

# Upload from local machine to VM
scp -P 4242 /path/on/local/ levelXX@<VM_IP>:/path/on/vm

Option 2: QEMU (Port Forwarding)

  1. Download the ISO
  2. Launch the VM with port forwarding so you can SSH directly from your host:
qemu-system-x86_64 -cdrom SnowCrash.iso -m 1024 -boot d \
  -netdev user,id=net0,hostfwd=tcp::4243-:4242 \
  -device e1000,netdev=net0
  1. SSH Connection using localhost and the forwarded port:
ssh level00@localhost -p 4243
# Password: level00

File transfer (SCP)

# Download from VM to local machine
scp -P 4243 levelXX@localhost:/path/on/vm /path/on/local/

# Upload from local machine to VM
scp -P 4243 /path/on/local/ levelXX@localhost:/path/on/vm

Login credentials

Each level has the same username and password initially:

  • Username: levelXX (e.g., level00, level01)
  • Password: levelXX (same as username)

After retrieving a flag, use it to log into the next level:

su level00
# Enter the flag as password

Tools used

  • John the Ripper - password cracking
  • Wireshark - network analysis
  • Ghidra - binary decompilation

Authors

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages