Hacked Cyberdefenders
Category : Digital Forensics Medium " Linux FTK Disk"
Q1 What is the system timezone?

Q2 Who was the last user to log in to the system?

Q3 What was the source port the user 'mail' connected from?
Q4 How long was the last session for user 'mail'? (Minutes only)

Q5 Which server service did the last user use to log in to the system?
Q6 What type of authentication attack was performed against the target machine


Q8 How many users have a login shell?

Q9 What is the password of the mail user?


Q10 Which user account was created by the attacker?

Q11 How many user groups exist on the machine?

Q12 How many users have sudo access?

Q13 What is the home directory of the PHP user?
Q14 What command did the attacker use to gain root privilege? (Answer contains two spaces).

Q15 Which file did the user 'root' delete?

Q16 Recover the deleted file, open it and extract the exploit author name.


Q17 What is the content management system (CMS) installed on the machine?

Q18 What is the version of the CMS installed on the machine?


Q19 Which port was listening to receive the attacker's reverse shell?


Last updated