Fork me on GitHub

MontréHack

Apprentissage et partage de connaissance sur la sécurité informatique en travaillant des problèmes appliqués.

Learning and sharing knowledge on IT security by solving technical challenges.

Troisième mercredi du mois
Third wednesday of every month

Archives | Learning | Mailing list | Group Chat | Calendar |

Prochaine édition: Mercredi le 19 septembre

English version

La prochaine édition de Montréhack aura lieu mercredi le 19 septembre 2018.

:clipboard: : Enregistrement obligatoire

A NorthSec Space Flag!

Les drapeaux de l’espace de NorthSec

Pour cette édition de MontréHack, vous aurez l’occasion de revisiter l’univers de NorthSec 2018. Alors que la colonisation de Mars est en plein essor, de nombreuses entreprises se développent autour de nouvelles opportunités lié à la planète rouge.

Vous aurez accès aux sites web de deux organisations:

Outils et expérience requis

Les défis / The Challenges

Space Shop

The first Mars online shop was launched. The website has a bug bounty open to Mars citizen.

Objective 1: Can you access users passwords ?

Unfortunally, the registration is closed. The only information the client is willing to give is this SQL snippet that was use in a test environment. insert into user(email, name, password) values ('testuser@spaceshop.com','test','test');

Objective 2: If you bend the scope, you might be able access more information..

http://xss.lol:8007/

Spice-X - Part 1

The mysterious Company Spice X is very discreet about its research projects.

Spice X was about to announce a new factory but, took down the page minutes after the accidental publication.

Objective: Can you recover the page that was taken offline?

Their is another rumor floating around. A whistle blower will release compromising information about the company.

Objective: Can you find who is the whistle blower ready to leak information about Spice X?

http://xss.lol:8000/

Spice-X - Part 2

You previously find out about the whistler blower that is preparing a publication.

Apparently the Spice X official website is hosting some internal document.

Objective: Can you find out about Spice X secret activity details before the whistler blower take action.

http://xss.lol:8000/

ESET

473 Ste-Catherine Ouest, Suite 300, Montréal, QC H3B 1B1, Canada

L’entrée est sur le côté de l’immeuble, près de l’église.

Quand

Mercredi le 19 septembre de 18h à 21h (suivi de bières au Bénélux)

Comment

Remerciements

Présenté et créé par Philippe Arteau (@h3xstream) dans le cadre de NorthSec 2018

Next edition: Wednesday September 19th

The next edition of Montrehack will be held on Wednesday September 19th.

:clipboard: : Registration is mandatory

A NorthSec Space Flag!

NorthSec’s Space Flags

For this edition, we will revisit the universe of NorthSec 2018. As Mars’ colonization is underway, many businesses develop around the new opportunities provided by the red planet.

You will have access to the web sites of two organizations:

Tools and Experience Required

Where

ESET

473 Ste-Catherine Ouest, Suite 300, Montréal, QC H3B 1B1, Canada

The entrance is on the side of the building, close to the church.

When

Wednesday September 19th from 6pm to 9pm (followed by drinks at Bénélux)

How

Credits

Presented and created by Philippe Arteau (@h3xstream) for NorthSec 2018


Vous souhaitez présenter? / Interested to present a challenge?


Sponsors // Partenaires

Brasserie Benelux