Hack the Cube - Portal characters around a hacked Companion Cube

Test Chamber Archives

Meerkat
Enter Test Chamber
Easy Linux

263 Suricata alerts. A BonitaSoft server. Three attacker IPs rotating through credential stuffing, CVE-2022-25237, and SSH key persistence. Chell reconstructs the full kill chain from a PCAP and a JSON file.

Validation
Enter Test Chamber
Easy Linux

The INSERT was parameterized. The SELECT wasn't. A dropdown menu that nobody thought to intercept, a database user with every privilege imaginable, and a password reused from PHP config all the way to root.