CCDC 2019 Qualifier Questions

Materials

You might need this. Here is the packet from 2019 Midwest Qualifiers: Midwest Qualifier 2019 Packet

SOLVED Question 1: Why did these Palo-Alto FW rules fail?

My tried-and-tested rules failed during Qualifiers. It took me a total of 16 minutes to input them into the PA Web GUI. My first guess is it has something to do with NAT? Do I have to put the NAT IP Address into the destination address too? I have no idea how to implement NAT with a virtual router and my unmanaged router at home. I can't test NAT in my own lab environment.

Note: Rule "anything" is disabled. I use that for emergencies only. I don't set the "Default" rule, the PA will disallow everything with 0 rules.

SOLVED Question 2: Why can't I nmap/ping/reach services from the External Windows 10 host?

I tried playing with the IP and subnet mask on the Win 10 box. No dice. I had a PA any-any rule so I don't see how that was a problem either. Any ideas? I did not check the Windows FW.

Question 3: How do I keep Travis out?

I heard there was a Travis Firewall person that breaks into PA-FWs with vulnerable PA versions and root shells. How would I find a root shell on a PA box? Is there something underneath the CLI I can get to? I wonder if Linux is underneath the PAN-OS and I can do the usual (netstat -ln/ps aux/iptables) thing.

Question 4: Why did both Windows 2008 and Windows 8.1 DNS fail 75% into the competition?

I created Windows Firewall rules via Command-Line at around 11:30am. They were working great! I allowed DNS via Program Rule C:\Windows\System32\svchost.exe. Why did DNS suddenly fail when it was 3:30pm? I set the IPv4 DNS to 8.8.8.8 and 8.8.4.4. I could ping to 8.8.8.8 and visit websites by using IP addresses. DNS just wouldn't work. I had an any-any rule on the PA-FW.

Windows FW Pictures Windows 8.1:

Question 5: License key for Palo-Alto VM-100? Or another download?

I have an unlicensed version. Does anyone know a Director outside of MW region that has PA-keys and VMS? Or who I could contact to get a license key for practice?

Responses & Tips

Hopefully my questions make sense.
If you want to give tips, ideas, strategies or answers (especially strategies for a 2-person team):
Public: Reply to this blog.
Private: Email me at ASzampiasSWD@gmail.com

Solved

1. Must use NAT Public IP address in the Destination Source Address. Solved by Mr_Fourteen reddit.
2. Change default Gateway to point to PA FW. Switch as needed. Solved by dogpolls reddit.

Comments

Popular posts from this blog

Palo Alto for GNS3 CCDC Tutorial

Trace Labs Global Missing Persons CTF V

Release of CCDC ISE Manager Website