Standoff 13 main stage

STFware
STFware IT company
The company provides hosting services and develops software for organizations across various sectors. For instance, it maintains a ticket sales service and a platform for interaction between citizens and government authorities.

Scope

Outer perimeter:
it.stf 10.119.12.0/26,
hosting.stf 10.119.12.64/26,
10.119.14.0/24
Inner perimeter:
hosting.stf 10.149.18.0/23,
it.stf 10.149.16.0/23

Out of scope:

  1. all servers named logc.<office>.stf
  2. network 10.119.1.0/24
  3. SC SERVERS, SC USERS networks: 10.149.2.0/26, 10.149.4.0/26, 10.149.6.0/26, 10.149.8.0/26, 10.149.10.0/26, 10.149.12.0/26, 10.149.14.0/26, 10.149.16.0/26, 10.149.18.0/26, 10.149.20.0/26, 10.149.22.0/26, 10.149.24.0/26
  4. Accounts starting with "pt*"

Vulnerability reports

The tasks indicate where the vulnerabilities are located: on Gate hosts or in the DMZ and further within the infrastructure. Reports on vulnerabilities found in Gate are automatically verified upon flag submission. Reports on vulnerabilities found in the DMZ and within the infrastructure are verified by the jury.
When reporting a vulnerability, make sure to note where it was found. If it was discovered on Gate hosts, open the report in the relevant tab, select the vulnerability, and submit the flag. If it was found in the DMZ and further within the infrastructure, fill out a report for the jury.
Attacker metrics
Critical events
74reports
submitted
53critical events
triggered
Loading data
Difficulty:
Low
Medium
High
Master
Vulnerabilities
0vulnerabilities
discovered
Severity:
Critical: undefined
High: undefined
Medium: undefined
Low: undefined
Defender metrics
NoT1meToSleep
Monitoring
0
incidents
recorded
0
critical events
investigated

Results

Rank
Team
Triggered events
Event points
Discovered vulnerabilities
Vulnerability points
Total points
1
True0xA3
7
25,625
3
500
26,125
2
cR4.sh
7
24,237
5
1,500
25,737
3
Wetox
6
17,030
9
2,300
19,330
4
Radiant0x2A
6
12,156
3
700
12,856
5
ℭ𝔲𝔩𝔱
3
10,180
5
1,200
11,380
6
RHTxF13xSHD
3
1,535
9
2,500
4,035
7
Bulba Hackers
4
2,109
5
1,000
3,109
8
only_f4st
1
2,500
3
500
3,000
9
Kibers
3
2,125
3
500
2,625
10
DeteAct × SPbCTF
1
1,535
3
800
2,335
11
TSARKA
3
1,109
4
700
1,809
12
Jet_Infosystems
3
1,000
2
400
1,400
13
EvilBunnyWrote
0
0
5
1,300
1,300
13
Invuls
0
0
5
1,300
1,300
14
SecWare
0
0
4
800
800
14
T.H.R.E.A.T
1
0
4
800
800
15
MG.RT
0
0
3
700
700
15
5HM3L
2
0
4
700
700
15
Crypto Apes
0
0
4
700
700
16
4ak4ak
0
0
3
500
500
16
Baguette2Pain
2
0
2
500
500
16
GISCYBERTEAM
0
0
3
500
500
16
Wardagen
1
0
3
500
500
17
Data
0
0
2
400
400
18
DreamTeam
0
0
1
300
300
Overview
Critical events