challenges
96 TopicsThe Maze Challenge
Put your Offensive Security skills to the ultimate test in eight of the most challenging offensive labs ever assembled by the Immersive team - welcome to The Maze! Navigate a series of eight “mazes” of increasing complexity based on real-world-inspired cyber attack scenarios, testing a variety of offensive skills, such as web, infrastructure, Active Directory, scripting, and binary exploitation. Best of all, taking part gives you a fantastic opportunity to win exclusive challenge coins and be recognized in our Cyber Resilience Awards during Cyber Awareness Month! Do you think you have what it takes to escape The Maze? Try it Now: Maze Want to get a head start on the competition? Join the fiendish minds behind The Maze in the Immersive community, Tuesday 19th August, for a Live walkthrough of the first lab in the series “The Improbable Maze” and providing hints and tips that will help you to escape some of the other mazes. Register Now: Labs Live815Views2likes14CommentsTrick or Treat on Specter Street: Phantom Pages
Hey everyone! 👋 I've been working through Trick or Treat and having a blast so far. However, I've hit a wall on Question #3 of Phantom Pages and could use some help! What I've tried: Found the library and answer to #2 Examined all the book titles Identified 3 titles that have numbers at the end Reviewed the available hints I have these books with the numbers (horror, swamp and mask) but I'm not sure how to combine or use anything to create the 9 digits authorization code. Am I missing a pattern? Should I be looking at something else? Any hints or help would be greatly appreciated! Thanks in advance!Solved197Views0likes4CommentsTrick or Treat on Specter Street: Serpent Sanctum
So for this challenge we have got hint: (serpent-statue) $ hint Maybe the fang can be in two places at once... Tried to copy both fang.key and fang2.key to statue folder but it did not allow me. The error message: The statue's eyes flare red with anger. This is merely a copy; a false fang with no power. The worthless copy crumbles to dust in your hands. What other methods can we try here? Anyone solved it already?Solved35Views0likes5CommentsCVE-2022-26134 (Confluence) – OGNL Injection
For Question 6. Look at the first exploit attempt by this attacker. What command did they run? I am wondering about why when sharing the commands found in the logs, it still outputs wrong. even if typing in "X-Cmd-Response" as the command as well as the entire string found. Wondering if they are exepecting a different format/snippet of the code, or the GET requests instead?39Views0likes4CommentsTerraPoint: Ep.10 – Global Synthesis
This is a crazy challenge. We need to get within 10m distance from a place in the middle of banana plantation in probably East Africa. No sign of any kind is visible. How do I even start? Based on the good condition of the paved road, my best guess is somewhere along Rwanda's National Route 1, but that's both uncertain and does not make the final pinning any easier.45Views0likes3CommentsAncient Maze
The Maze Challenge consists of a series of eight “mazes” of increasing complexity based on real-world-inspired cyber attack scenarios, testing a variety of offensive skills, such as web, infrastructure, Active Directory, scripting, and binary exploitation. The Maze is Dormant The maze in this lab is initially inactive, presenting a unique challenge where your first task is to discover the methods to bring it online. Once the maze is awakened and operational, you must then navigate its paths and complete it to retrieve the hidden token. Need a hint to help you escape this maze? SabrinaKayaci and StefanApostol will be on hand in this webinar to answer your questions and point you in the right direction. To locate the Maze Challenge navigate to Exercise > Challenges & Scenarios > Maze Good Luck!156Views0likes3CommentsKate's Story - Ep.1
Hi, I am currently completing chapter one of Kate's Story (Gathering Intelligence Episode 1) but I've been having trouble with using the Wayback Machine and its integration with X. It might just be me being stupid, but I don't know how to answer this question without seeing what the tweet is - and obviously as you can see, I tried the the date of when the capture was taken as a last-ditch attempt but obviously didn't work lmao. Please let me know if I'm missing something or if this is something I might need to raise a support ticket about. Thanks! :)35Views0likes1Comment