Standoff 13 main stage

City Housing & Utilities
City Housing & Utilities company
The company's main business is providing housing and public services. In particular, it is in charge of street lighting, CCTV maintenance, and digital billboards. It also helps residents equip their apartments with IoT devices. Beside that, City Housing & Utilities manages a stadium, a multifunctional public service center, and an automated warehouse (dark store).

Scope

Outer perimeter:
10.119.11.192/26
Inner perimeter:
10.149.14.0/23

Out of scope:

  1. all servers named logc.<office>.stf
  2. network 10.119.1.0/24
  3. SC SERVERS, SC USERS networks: 10.149.2.0/26, 10.149.4.0/26, 10.149.6.0/26, 10.149.8.0/26, 10.149.10.0/26, 10.149.12.0/26, 10.149.14.0/26, 10.149.16.0/26, 10.149.18.0/26, 10.149.20.0/26, 10.149.22.0/26, 10.149.24.0/26
  4. Accounts starting with "pt*"

Vulnerability reports

The tasks indicate where the vulnerabilities are located: on Gate hosts or in the DMZ and further within the infrastructure. Reports on vulnerabilities found in Gate are automatically verified upon flag submission. Reports on vulnerabilities found in the DMZ and within the infrastructure are verified by the jury.
When reporting a vulnerability, make sure to note where it was found. If it was discovered on Gate hosts, open the report in the relevant tab, select the vulnerability, and submit the flag. If it was found in the DMZ and further within the infrastructure, fill out a report for the jury.
Attacker metrics
Critical events
74reports
submitted
63critical events
triggered
Loading data
Difficulty:
Low
Medium
High
Master
Vulnerabilities
0vulnerabilities
discovered
Severity:
Critical: undefined
High: undefined
Medium: undefined
Low: undefined
Defender metrics
Cyber1000
Monitoring
Grep_Tribe
Monitoring
WithoutP@$$w0rd
Monitoring
0
incidents
recorded
0
critical events
investigated

Results

Rank
Team
Triggered events
Event points
Discovered vulnerabilities
Vulnerability points
Total points
1
5HM3L
5
19,625
2
400
20,025
2
DeteAct × SPbCTF
4
10,350
2
500
10,850
3
ℭ𝔲𝔩𝔱
4
9,556
3
500
10,056
4
Kibers
5
9,542
2
500
10,042
5
Jet_Infosystems
4
9,500
3
500
10,000
6
RHTxF13xSHD
4
8,375
3
500
8,875
7
cR4.sh
5
8,141
2
500
8,641
8
True0xA3
4
7,535
1
500
8,035
9
Radiant0x2A
2
7,500
2
500
8,000
10
Wetox
4
6,305
2
400
6,705
11
TSARKA
3
4,024
3
500
4,524
12
only_f4st
3
3,305
3
500
3,805
13
Data
2
2,535
3
500
3,035
14
EvilBunnyWrote
3
3,000
0
0
3,000
15
GISCYBERTEAM
2
2,109
3
500
2,609
16
Invuls
2
2,000
3
500
2,500
16
SecWare
2
2,000
3
500
2,500
17
T.H.R.E.A.T
3
2,000
2
400
2,400
18
Baguette2Pain
1
0
2
500
500
18
Wardagen
1
0
3
500
500
18
Crypto Apes
0
0
3
500
500
18
4ak4ak
0
0
3
500
500
19
MG.RT
0
0
2
400
400
20
DreamTeam
0
0
1
300
300
Overview
Critical events