Standoff 13 main stage

Heavy Logistics
Heavy Logistics transport company
The company owns a railroad, an airport, and a seaport. Heavy Logistics also operates the traffic-light system in the capital

Scope

Outer perimeter:
10.119.12.192/26
Inner perimeter:
10.149.24.0/23

Out of scope:

  1. all servers named logc.<office>.stf
  2. network 10.119.1.0/24
  3. SC SERVERS, SC USERS networks: 10.149.2.0/26, 10.149.4.0/26, 10.149.6.0/26, 10.149.8.0/26, 10.149.10.0/26, 10.149.12.0/26, 10.149.14.0/26, 10.149.16.0/26, 10.149.18.0/26, 10.149.20.0/26, 10.149.22.0/26, 10.149.24.0/26
  4. Accounts starting with "pt*"

Vulnerability reports

The tasks indicate where the vulnerabilities are located: on Gate hosts or in the DMZ and further within the infrastructure. Reports on vulnerabilities found in Gate are automatically verified upon flag submission. Reports on vulnerabilities found in the DMZ and within the infrastructure are verified by the jury.
When reporting a vulnerability, make sure to note where it was found. If it was discovered on Gate hosts, open the report in the relevant tab, select the vulnerability, and submit the flag. If it was found in the DMZ and further within the infrastructure, fill out a report for the jury.
Attacker metrics
Critical events
27reports
submitted
16critical events
triggered
Loading data
Difficulty:
Low
Medium
High
Master
Vulnerabilities
0vulnerabilities
discovered
Severity:
Critical: undefined
High: undefined
Medium: undefined
Low: undefined
Defender metrics
tSOC
Monitoring
0
incidents
recorded
0
critical events
investigated

Results

Rank
Team
Triggered events
Event points
Discovered vulnerabilities
Vulnerability points
Total points
1
True0xA3
5
18,500
6
1,400
19,900
2
ℭ𝔲𝔩𝔱
1
10,000
5
1,100
11,100
3
DeteAct × SPbCTF
1
7,225
3
500
7,725
4
GISCYBERTEAM
1
6,141
4
800
6,941
5
Kibers
1
4,250
2
300
4,550
6
Jet_Infosystems
1
0
6
2,000
2,000
7
RHTxF13xSHD
1
0
5
1,300
1,300
8
Radiant0x2A
1
0
4
1,100
1,100
9
Wetox
0
0
3
800
800
10
TSARKA
0
0
2
600
600
11
SecWare
0
0
3
500
500
11
EvilBunnyWrote
0
0
3
500
500
11
Crypto Apes
0
0
3
500
500
11
only_f4st
0
0
3
500
500
11
Invuls
0
0
3
500
500
11
T.H.R.E.A.T
1
0
2
500
500
11
Wardagen
1
0
3
500
500
11
Data
0
0
2
500
500
11
5HM3L
0
0
3
500
500
12
Baguette2Pain
0
0
2
400
400
13
MG.RT
0
0
1
200
200
13
cR4.sh
1
0
1
200
200
14
Bulba Hackers
1
0
0
0
0
Overview
Critical events