Black cats are prowling, pumpkins are glowing and witches are waltzing – it’s Halloween! Here at Immersive Labs, we love to celebrate the holidays. This year is definitely in need of some fun, so to whet your vampire-toothed whistle, we’ve put together a series of spook-tacular murder mystery CTF-style labs that require a range of cyber skills.
Here’s how it starts...
You and a friend have checked into a hotel for an infosec conference. At reception, you are invited to a Halloween-themed party. Later that evening, the event is well attended; everyone is dressed for the occasion, revelling in the fake-blood frivolities of the Halloween party. After dinner, you mingle with the other guests, drinking pumpkin punch and bloody Marys. The evening is all fun and games until a murder takes place… It’s your job to figure out who did it, but of course, the killer hasn’t made it easy for you. You’ll need to demonstrate your digital dexterity and coding competence to work out the murderer’s identity.
The first lab in the series focuses on infrastructure hacking, which is pretty simple when you know what you're looking for. Can you find any open ports after scanning the target IP address? What is that port commonly associated with? A quick look around the desktop should also provide you with a crucial tool. What could help you find out who was staying at the hotel?
Moving on from infrastructure to web app hacking, in part two you’ll need to use your knowledge of SQL injection to retrieve data about who attended the party. What parameter might be vulnerable? Following that, the third CTF is a nested archive challenge, sort of like a Linux-based Russian doll. What will you discover when you get to the center?
No murder mystery would be complete without some forensic DNA analysis. And of course, because this is a cyber challenge, the best way to access files of interest is through the aptly-named program Autopsy, through which you can undertake some cyber forensic analysis. See what we did there?
And finally, the fifth lab will reveal who the murderer is, provided you can craft some nifty server-side template injections. It seems that the killer is scarily into blogging and creepy literature. He’s also a bit of a poet, believe it or not. Can you find the poem he’s hidden?
All of these Halloween murder mystery labs are now available on Community mode, so if you’ve always fancied trying the platform but were unsure about how to access it, now’s your chance. It’s all completely free: no contracts, no cash, no commitments. All you need to get started is yourself, your email address, and the code GIMMEFREELABS.
Ready to solve the mystery?
30 October 2020
Latest Blog posts
Why You Shouldn’t Blindly Trust the Software Supply Chain
23 November 2021
Welcoming Snap Labs to the team – and accelerating towards the future of Immersive Labs
15 November 2021
Patch Newsday: Wild CVEs & CISA Directives
10 November 2021
Patch Newsday: 12 October 2021 – Spooky Spooler and Sinister Scores
13 October 2021
Building cyber resilience for the Financial Services sector with breadth and at scale
4 October 2021
OWASP Top 10 2021 has finally landed – here’s why you should care
27 September 2021