TeamCity Takedown: Breach, Backup, and Break-in.

2 months ago 27
BOOK THIS SPACE FOR AD
ARTICLE AD

Josh Beck

iCSI@NEISD Security Operations Center Classroom (San Antonio, Texas)

This CTF will work for advanced students seeking more Kali Linux experience. Inspired by @IPPSEC’s awesome breakdown of the ‘Runner’ box on Hack the Box, this activity covers similar ground with a hands-on approach.

In this CTF, students will:

Explore CI/CD (a key concept for the Security+ Exam)Analyze why CVE-2023–42793 exists within this version of the TeamCity web appDownload and break down exploit codeCreate and enumerate a database backup once initial web access is obtained.Gain initial ssh access and escalate to root

Writing this one helped me understand the CVE — great for advanced students in cybersecurity classrooms!

Directions with downloadable VM Here:

https://humble-raptor-f30.notion.site/TeamCity-Takedown-Breach-Backup-and-Break-in-568e00735e894bd69fa3dac255b1ac3a?pvs=4

Read Entire Article