Standoff 11
Cyber exercise
finished
City Housing & Utilities company
The company's main business is providing housing and public services. In particular, it is in charge of street lighting, CCTV maintenance, and digital billboards. It also helps residents equip their apartments with IoT devices. Beside that, City Housing & Utilities manages a stadium, a multifunctional public service center, and an automated warehouse (dark store).
Scope
Outer perimeter:
10.119.11.192/26
Inner perimeter:
10.149.14.0/23
10.119.11.192/26
Inner perimeter:
10.149.14.0/23
Out of scope:
- all servers named logc.<office>.stf
- network 10.119.1.0/24
- SC SERVERS, SC USERS networks: 10.149.2.0/26, 10.149.4.0/26, 10.149.6.0/26, 10.149.8.0/26, 10.149.10.0/26, 10.149.12.0/26, 10.149.14.0/26, 10.149.16.0/26, 10.149.18.0/26, 10.149.20.0/26, 10.149.22.0/26, 10.149.24.0/26
- Accounts starting with "pt*"
Vulnerability reports
The tasks indicate where the vulnerabilities are located: on Gate hosts or in the DMZ and further within the infrastructure. Reports on vulnerabilities found in Gate are automatically verified upon flag submission. Reports on vulnerabilities found in the DMZ and within the infrastructure are verified by the jury.
When reporting a vulnerability, make sure to note where it was found. If it was discovered on Gate hosts, open the report in the relevant tab, select the vulnerability, and submit the flag. If it was found in the DMZ and further within the infrastructure, fill out a report for the jury.
Attacker metrics
Critical events
63reports
submitted
submitted
45critical events
triggered
triggered
Loading data
Difficulty:
Low
Medium
High
Master
Vulnerabilities
0vulnerabilities
discovered
discovered
Severity:
Critical: undefined
High: undefined
Medium: undefined
Low: undefined
Defender metrics
0
incidents
recorded
recorded
0
critical events
investigated
investigated
Results
Rank
Team
Triggered events
Event points
Discovered vulnerabilities
Vulnerability points
Total points
1
True0xA3
5
21,049
1
75
21,124
2
Codeby
5
10,807
0
0
10,807
3
Invuls
4
9,849
0
0
9,849
4
ДРТ & ℭ𝔲𝔩𝔱
4
9,420
0
0
9,420
5
DeteAct × SPbCTF
4
5,616
0
0
5,616
6
Wetox
4
2,969
1
150
3,119
7
TSARKA
2
2,134
0
0
2,134
8
Bulba Hackers
1
1,750
0
0
1,750
9
Wardagen
3
1,573
1
150
1,723
10
NOMADS
2
1,430
1
75
1,505
11
5HM3L
2
892
0
0
892
12
APTeam
1
857
0
0
857
13
EvilBunnyWrote
2
562
1
150
712
14
LocalGhost
2
316
0
0
316
15
Инфосистемы Джет
2
170
0
0
170
16
Baguette2Pain
0
0
1
150
150