CCDC 2019 Qualifier Questions
Materials
You might need this. Here is the packet from 2019 Midwest Qualifiers: Midwest Qualifier 2019 PacketSOLVED Question 1: Why did these Palo-Alto FW rules fail?
My tried-and-tested rules failed during Qualifiers. It took me a total of 16 minutes to input them into the PA Web GUI. My first guess is it has something to do with NAT? Do I have to put the NAT IP Address into the destination address too? I have no idea how to implement NAT with a virtual router and my unmanaged router at home. I can't test NAT in my own lab environment.Note: Rule "anything" is disabled. I use that for emergencies only. I don't set the "Default" rule, the PA will disallow everything with 0 rules.
SOLVED Question 2: Why can't I nmap/ping/reach services from the External Windows 10 host?
I tried playing with the IP and subnet mask on the Win 10 box. No dice. I had a PA any-any rule so I don't see how that was a problem either. Any ideas? I did not check the Windows FW.Question 3: How do I keep Travis out?
I heard there was a Travis Firewall person that breaks into PA-FWs with vulnerable PA versions and root shells. How would I find a root shell on a PA box? Is there something underneath the CLI I can get to? I wonder if Linux is underneath the PAN-OS and I can do the usual (netstat -ln/ps aux/iptables) thing.Question 4: Why did both Windows 2008 and Windows 8.1 DNS fail 75% into the competition?
I created Windows Firewall rules via Command-Line at around 11:30am. They were working great! I allowed DNS via Program Rule C:\Windows\System32\svchost.exe. Why did DNS suddenly fail when it was 3:30pm? I set the IPv4 DNS to 8.8.8.8 and 8.8.4.4. I could ping to 8.8.8.8 and visit websites by using IP addresses. DNS just wouldn't work. I had an any-any rule on the PA-FW.Windows FW Pictures Windows 8.1:
Question 5: License key for Palo-Alto VM-100? Or another download?
I have an unlicensed version. Does anyone know a Director outside of MW region that has PA-keys and VMS? Or who I could contact to get a license key for practice?Responses & Tips
Hopefully my questions make sense.If you want to give tips, ideas, strategies or answers (especially strategies for a 2-person team):
Public: Reply to this blog.
Private: Email me at ASzampiasSWD@gmail.com
Solved
1. Must use NAT Public IP address in the Destination Source Address. Solved by Mr_Fourteen reddit.2. Change default Gateway to point to PA FW. Switch as needed. Solved by dogpolls reddit.
Comments
Post a Comment