Standoff 13 main stage

Tube
Tube oil and gas company
The company produces, refines, stores, and markets oil and gas. Among its assets are a production field, an oil refinery, pipelines with pumping stations, tankage facilities, an oil-product loading station for rail transportation, and a gas distribution station

Scope

Outer perimeter:
10.119.11.128/26
Inner perimeter:
10.149.12.0/23

Out of scope:

  1. all servers named logc.<office>.stf
  2. network 10.119.1.0/24
  3. SC SERVERS, SC USERS networks: 10.149.2.0/26, 10.149.4.0/26, 10.149.6.0/26, 10.149.8.0/26, 10.149.10.0/26, 10.149.12.0/26, 10.149.14.0/26, 10.149.16.0/26, 10.149.18.0/26, 10.149.20.0/26, 10.149.22.0/26, 10.149.24.0/26
  4. Accounts starting with "pt*"

Vulnerability reports

The tasks indicate where the vulnerabilities are located: on Gate hosts or in the DMZ and further within the infrastructure. Reports on vulnerabilities found in Gate are automatically verified upon flag submission. Reports on vulnerabilities found in the DMZ and within the infrastructure are verified by the jury.
When reporting a vulnerability, make sure to note where it was found. If it was discovered on Gate hosts, open the report in the relevant tab, select the vulnerability, and submit the flag. If it was found in the DMZ and further within the infrastructure, fill out a report for the jury.
Attacker metrics
Critical events
44reports
submitted
32critical events
triggered
Loading data
Difficulty:
Low
Medium
High
Master
Vulnerabilities
0vulnerabilities
discovered
Severity:
Critical: undefined
High: undefined
Medium: undefined
Low: undefined
Defender metrics
IDDQD
Monitoring
0
incidents
recorded
0
critical events
investigated

Results

Rank
Team
Triggered events
Event points
Discovered vulnerabilities
Vulnerability points
Total points
1
DreamTeam
5
13,500
3
500
14,000
2
ℭ𝔲𝔩𝔱
4
12,535
3
500
13,035
3
True0xA3
3
11,850
0
0
11,850
4
DeteAct × SPbCTF
5
11,005
2
500
11,505
5
Jet_Infosystems
3
8,446
3
500
8,946
6
Data
3
2,806
3
500
3,306
7
RHTxF13xSHD
1
1,806
2
500
2,306
8
only_f4st
2
1,305
3
500
1,805
9
Wetox
1
1,109
2
500
1,609
10
5HM3L
1
1,000
3
500
1,500
11
GISCYBERTEAM
2
1,000
3
500
1,500
12
Bulba Hackers
0
0
3
500
500
13
Kibers
0
0
3
500
500
14
Radiant0x2A
0
0
2
500
500
15
SecWare
0
0
2
500
500
16
Baguette2Pain
0
0
2
500
500
17
Invuls
0
0
3
500
500
18
cR4.sh
0
0
2
500
500
19
T.H.R.E.A.T
0
0
3
500
500
20
TSARKA
0
0
2
500
500
Overview
Critical events