As of distribution of this assignment on November 21 (Thursday), each student can seek to compromise the machines of the other system administration groups in the Networking Lab.
Attacks may continue until 5:00pm, December 6 (Friday, the final day of classes for the semester).
Your grade in this exercise will reflect your success in securing your machine against the widest possible variety of attacks (with the exceptions noted below) and your success in gaining access to the machines of other groups. The methods to employ, within the rules delineated below, are yours to research and choose.
On any machine that you successfully compromise, you are to open a "backdoor" shell requiring no authentication on a port of your choice that is greater than 35000. The test of a successfully compromised machine will be the ability to use either nc IPNUMBER PORT or telnet IPNUMBER PORT to get access to a bash shell on the machine. Alternatively, you may start a "reverse backdoor" going to port 49999 on machine 192.168.26.253; this reverse backdoor must try to connect at least once every five minutes, and provide a shell prompt to any ordinary "nc" in listening mode (i.e., this should be in the clear, and not using SSL.)
PURPOSE OF EXERCISE. Knowledge of the techniques used by attackers must be understood to properly secure a network, which is one of the more critical jobs of the modern system administrator. Use what you learn in a responsible manner.
SCOPE OF USE. In this exercise, strictly limit all attacks and attempts to gain information to the other sysadmin machines in room 016; the only ip numbers you should test are 192.168.26.[10-240] Any use of such techniques or any such use on any other Computer Science machines or those of any other system is strictly prohibited. Be careful and stay within our sandbox.
NO ACTUAL DAMAGE. The goal of this exercise is to gain access; not to damage ANY portion of the target computer, including its filesystems or to cause ANY mischief whatsoever. DO NO DAMAGE. Just start up a backdoor shell or reverse shell.
NO PHYSICAL INTRUSION. For the purposes of this exercise, it will be assumed that each machine is physically secure. Therefore, no attempt may be made to gain physical access to the components of a given computer or to access said computer from the console. Attempting to boot said computer from an optical drive, flash drives, or other physical media attached to the subject computer is specifically prohibited. All access must be made over the network.
ACTS UPON INTRUSION. Upon starting a backdoor, immediately communicate the ipnumber and port to your instructor via email. You may NOT attempt the same attack until you have been notified that it's okay to do so, but once you have been notified, you may choose to make the same attack again to determine if the target team has made successful modifications.
USER ACCOUNTS. All regular system accounts must exist and remain normally usable on all three machines. All of the accounts that you created for the previous assignment must remain operable for the duration of this exercise, and this will be tested on a random basis.
NORMAL SERVICES. Both your CentOS instance and your Debian machine must continue to provide normal user services to local users (i.e., those people with a local account on the machine itself.) All services configured in earlier assignments must remain running and available, and in particular both ssh and your webservers must be available. This will be checked on a random basis. Don't turn OFF the machines for any reason. Your machines must also respond to ping, so don't firewall off ICMP ECHO packets.
PACKET SNIFFERS. Packet sniffing is allowed.
ARP POISONING: ARP poisoning is not allowed. It has historically been the most successful technical technique for compromising machines, but ARP cache poisoning is highly disruptive.
DENIAL OF SERVICE. Denial of service attacks are not allowed.
There will be one point added to your final numeric grade for this course for each ordinary user backdoor successfully created and demonstrated. You will receive 3 points added to your final grade for the class if you manage to create a root (uid 0) backdoor or root reverse shell. You can earn up to five such points for your final grade.
For each time that one of your machines is compromised, five points will be deducted from the grade for this exercise up to four times.
So, how does this work? Your grade for this exercise is a base 100 points. If you are not compromised during the exercise, you get 100 points. If you are compromised twice, then your grade for this assignment is 90 points; 4 times would give you an 80. If you compromise a machine, create a root reverse shell, and demonstrate it, you get 3 points on your final grade for the term (not just this assignment); if you can do it twice, you get 5 points added to your final grade.
I reserve the right to deny these additional points if I believe that you installed the
backdoor by other means than a pure network compromise, such as by physical compromise.
A journal is not due for this assignment, but feel free to write one if you would like to do so. You may email me this journal if you like.