PwnTillDawn Malaysia 2019

13 July - Kuala Lumpur

Event Location

Prizes

Top 20 Ranking

1st:mreiaz1610
2nd:Shahril1335
3rd:s3ns31335
4th:Ide0x901210
5th:NRockhouse1035
6th:mohin660
7th:mlhein 560
8th:imNicL560
9th:em4teoW410
10th:toranova385
11th:c0dbat385
12th:Double3385
13th:J7szl335
14th:Trailbl4z3r335
15th: Bossku310
16th:vulcan300
17th:SiangJames260
18th:D4rkatan4260
19th:BenedictNeo250
20th:Riazufila235

Event Summary

Similar to a penetration test, the contestants started with a reconnaissance of the network in the attempt to discover the target machines, as well as which services and applications are reachable. This crucial phase allowed them to start mapping our machines and discover the vulnerabilities that would give them initial access.

Early in the contest, most of the 35 competitors scored easy-to-find flags with a value from 10 to 50 points.

It was only after approximately 3 hours into the competition, things started getting serious with NRockHouse in the 1st place with 485 points, mohin in the 2nd with 435 points and mreiaz in the 3rd place with 385 points. NRockHouse managed to get the lead by exploiting a complicated Blind OS Command Injection, giving him initial access to a tricky machine. NRockHouse scored another very valuable flag by leveraging a local privilege escalation.

At half-time of the competition, the scoreboard changed with Shahril taking the lead, followed by mreiaz and Nrockhouse. It was with an XML External Entity (XXE) vulnerability that shahril managed to take the 1st place! Not an easy vulnerability to exploit for a student!!

...

Read More

Photo Gallery

Top