diff --git a/05-dns-service.md b/05-dns-service.md new file mode 100644 index 0000000..d0a45df --- /dev/null +++ b/05-dns-service.md @@ -0,0 +1,281 @@ +# DNS Service (BIND) + +## Overview + +DNS translates domain names to IP addresses (forward lookup) and IP addresses to domain names (reverse lookup). + +- **Forward lookup**: `ncaecybergames.org` → `192.168.8.2` +- **Reverse lookup**: `192.168.8.2` → `ncaecybergames.org` + +--- + +## Service Name + +- `named` (not `bind`) + +```bash +systemctl status named +sudo systemctl start named +sudo systemctl enable named +``` + +--- + +## Configuration Locations + +### Ubuntu +``` +/etc/bind/ +├── named.conf # Main config (includes other files) +├── named.conf.options # Server options +├── named.conf.local # Local zone definitions +├── named.conf.default-zones # Default zones (localhost, etc.) +├── db.empty # Template file to copy for new zones +├── db.local # Localhost zone file +├── db.127 # Localhost reverse zone +└── zones/ # Your custom zone files (create this) +``` + +### CentOS/RHEL +Configuration may be in a different location - check `/etc/named/` or `/var/named/` + +--- + +## Key Concepts + +### Zone Files +- **Forward zone**: Maps domain names → IP addresses (A records) +- **Reverse zone**: Maps IP addresses → domain names (PTR records) + +### Include Structure +The main `named.conf` typically includes other config files: +``` +include "/etc/bind/named.conf.options"; +include "/etc/bind/named.conf.local"; +include "/etc/bind/named.conf.default-zones"; +``` + +### allow-update Directive + +Controls whether dynamic DNS updates are permitted for a zone: + +``` +zone "example.org" IN { + type master; + file "/etc/bind/zones/forward.example.org"; + allow-update { none; }; # No dynamic updates allowed +}; +``` + +| Value | Meaning | +|-------|---------| +| `{ none; }` | No updates allowed (static zone, manual edits only) | +| `{ key mykey; }` | Allow updates signed with a specific TSIG key | +| `{ 192.168.8.5; }` | Allow updates from a specific IP address | + +**For competition: Always use `{ none; };`** - prevents attackers from remotely modifying your DNS records. + +--- + +## Setting Up DNS Zones + +### Step 1: Add Zone Definitions + +Edit the zones config file (Ubuntu: `named.conf.default-zones`): +```bash +sudo nano /etc/bind/named.conf.default-zones +``` + +Add a **forward lookup zone**: +``` +zone "ncaecybergames.org" IN { + type master; + file "/etc/bind/zones/forward.ncaecybergames.org"; + allow-update { none; }; +}; +``` + +Add a **reverse lookup zone**: +``` +zone "8.168.192.in-addr.arpa" IN { + type master; + file "/etc/bind/zones/reverse.ncaecybergames.org"; + allow-update { none; }; +}; +``` + +**Important**: For reverse zones, write the network portion of the IP **backwards**: +- IP: `192.168.8.x` → Zone: `8.168.192.in-addr.arpa` + +--- + +### Step 2: Create Zone Files Directory + +```bash +sudo mkdir /etc/bind/zones +``` + +--- + +### Step 3: Copy Template Files + +Copy the empty template (preserves correct ownership and permissions): +```bash +sudo cp /etc/bind/db.empty /etc/bind/zones/forward.ncaecybergames.org +sudo cp /etc/bind/db.empty /etc/bind/zones/reverse.ncaecybergames.org +``` + +**Why copy instead of create from scratch?** +- Preserves correct ownership (`root:bind`) +- Preserves correct permissions (`644`) +- If permissions/ownership are wrong, bind can't read the files + +Check permissions: +```bash +ls -l /etc/bind/zones/ +``` + +--- + +### Step 4: Configure Forward Zone File + +```bash +sudo nano /etc/bind/zones/forward.ncaecybergames.org +``` + +Example forward zone file: +``` +$TTL 604800 +@ IN SOA ncaecybergames.org. root. ( + 2 ; Serial (INCREMENT THIS ON EVERY CHANGE!) + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL + +@ IN NS sandbox-ubuntu. +sandbox-ubuntu IN A 192.168.8.2 +www IN A 192.168.8.2 +``` + +**Key points:** +- Replace `localhost` with your domain (`ncaecybergames.org.`) +- Replace `localhost` after `NS` with your server hostname (`sandbox-ubuntu.`) +- **Always increment the serial number** when making changes (1→2→3...) +- Add A records for each subdomain + +--- + +### Step 5: Configure Reverse Zone File + +```bash +sudo nano /etc/bind/zones/reverse.ncaecybergames.org +``` + +Example reverse zone file: +``` +$TTL 604800 +@ IN SOA ncaecybergames.org. root.ncaecybergames.org. ( + 2 ; Serial (INCREMENT THIS ON EVERY CHANGE!) + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL + +@ IN NS sandbox-ubuntu. +2 IN PTR www.ncaecybergames.org. +2 IN PTR sandbox-ubuntu.ncaecybergames.org. +``` + +**Key points:** +- For reverse zones, domain names end with a **period** (`.`) +- PTR record uses only the **host portion** of IP (for `192.168.8.2`, just use `2`) +- Multiple PTR records can point to the same IP + +--- + +## Start and Test DNS + +### Start the Service +```bash +sudo systemctl start named +systemctl status named +``` + +If it fails to start, check for typos in your config files (missing semicolons, periods, spaces). + +--- + +### Configure Client to Use Your DNS Server + +Edit `/etc/resolv.conf`: +```bash +sudo nano /etc/resolv.conf +``` + +Add your DNS server: +``` +nameserver 192.168.8.2 +``` + +Or add to netplan (`/etc/netplan/*.yaml`): +```yaml +nameservers: + addresses: + - 192.168.8.2 +``` + +--- + +## Testing DNS + +### Using nslookup + +Forward lookup: +```bash +nslookup www.ncaecybergames.org +``` + +Reverse lookup: +```bash +nslookup 192.168.8.2 +``` + +### Using Browser +Navigate to `http://www.ncaecybergames.org` - should load your web server. + +--- + +## Troubleshooting + +### Service Won't Start +- Check for typos in zone files (missing semicolons, periods) +- Check file permissions (`644`) and ownership (`root:bind`) +- Check config syntax: `named-checkconf` +- Check zone file syntax: `named-checkzone ncaecybergames.org /etc/bind/zones/forward.ncaecybergames.org` + +### DNS Not Resolving +- Verify service is running: `systemctl status named` +- Check `/etc/resolv.conf` has your DNS server listed +- Test with `nslookup` to isolate DNS vs other issues + +### Common Mistakes +- Forgetting to increment serial number after changes +- Missing periods at end of domain names in reverse zone files +- Wrong file permissions/ownership +- Typos in IP addresses or domain names +- Missing semicolons in config files + +--- + +## Quick Reference + +| Task | Command | +|------|---------| +| Check service status | `systemctl status named` | +| Start service | `sudo systemctl start named` | +| Restart after config change | `sudo systemctl restart named` | +| Check config syntax | `named-checkconf` | +| Check zone syntax | `named-checkzone DOMAIN ZONEFILE` | +| Forward lookup | `nslookup DOMAIN` | +| Reverse lookup | `nslookup IP` | diff --git a/05-dns-rsync-cron.md b/06-rsync-cron.md similarity index 82% rename from 05-dns-rsync-cron.md rename to 06-rsync-cron.md index 800cd64..a91f79b 100644 --- a/05-dns-rsync-cron.md +++ b/06-rsync-cron.md @@ -1,36 +1,4 @@ -# DNS, Rsync, and Cron Services - -## DNS Service (BIND) - -### Service Name -- `named` (most distributions) - -### Configuration Location -- Ubuntu: `/etc/bind/` -- CentOS: May be in different location - -### Check Service -```bash -systemctl status named -``` - -### Basic Concept -DNS translates domain names to IP addresses (forward lookup) and IP addresses to domain names (reverse lookup). - -**Forward lookup**: `example.com` → `192.168.1.100` -**Reverse lookup**: `192.168.1.100` → `example.com` - -### Key Files (Bind) -- `named.conf` - Main configuration -- Zone files - Define DNS records for domains - -**This is a complex service** - requires understanding of: -- Zone files -- DNS record types (A, PTR, CNAME, MX, etc.) -- Forward vs reverse zones -- DNS hierarchy - ---- +# Rsync and Cron Services ## Rsync - File Synchronization/Backup diff --git a/07-active-connection-defense.md b/07-active-connection-defense.md deleted file mode 100644 index 5611c41..0000000 --- a/07-active-connection-defense.md +++ /dev/null @@ -1,293 +0,0 @@ -# Active Connection Defense - -## Overview -Monitoring and managing active network connections is critical during competitions. This guide covers tools for identifying who's connected to your system and how to terminate malicious connections. - -## Core Monitoring Tools - -### netstat - Network Statistics - -**Most useful form**: -```bash -sudo netstat -tunap -``` - -**Breakdown**: -- `-t` = TCP connections -- `-u` = UDP connections -- `-n` = Show numeric ports (22 instead of "ssh") -- `-a` = Show listening and established connections -- `-p` = Show process IDs (requires sudo) - -**Output columns**: -``` -Proto Local Address Foreign Address State PID/Program -tcp 192.168.195.100:22 192.168.195.2:51736 ESTABLISHED 265408/sshd -``` - -**Common filters**: -```bash -netstat -tunap | grep ESTABLISHED # Only active connections -netstat -tunap | grep :22 # Only SSH connections -netstat -tunap | less # Scroll through output -``` - -### ss - Socket Statistics - -Modern replacement for netstat. Similar syntax: - -```bash -ss # Basic output (lots of info) -ss | grep ESTAB # Only established connections -ss -tunap # Same flags as netstat -``` - -**Advantage**: ss is installed on more modern systems by default. - -### w - Who is logged in - -```bash -w -``` - -**Shows**: -- Username -- From where (IP address or `:0` for local console) -- Login time -- What they're doing - -**Example output**: -``` -USER FROM WHAT -sandbox :0 -bash -bob 192.168.195.2 -bash -jenny 192.168.195.2 -bash -``` - -**Key indicator**: -- `:0` = Local console (physically at the machine) -- IP address = Remote connection (SSH, etc.) - -## Finding Process Information - -### top - Interactive Process Viewer - -```bash -top -``` - -- Shows CPU/memory usage -- Lists running processes -- Press `q` to quit - -### htop - Enhanced Process Viewer - -```bash -htop # If installed (not always available) -``` - -More colorful and interactive than `top`. - -### ps - Process Status - -```bash -ps aux # All processes, all users -ps aux | grep ssh # Find SSH processes -``` - -## Killing Connections - -### Kill by Process ID (PID) - -1. **Find the PID**: -```bash -sudo netstat -tunap -# Example output shows PID 265465 for jenny's SSH connection -``` - -2. **Kill the process**: -```bash -sudo kill 265465 -``` - -**From the user's perspective**: Connection closes immediately -``` -Connection to 192.168.195.100 closed by remote host. -``` - -### Kill by Username (pkill) - -```bash -sudo pkill -kill -u jenny # Kill all processes for user jenny -sudo pkill -kill -u bob # Kill all processes for user bob -``` - -**Warning**: This kills ALL processes for that user, including: -- Active SSH sessions -- Running programs -- Background jobs - -### Kill Signal Types - -```bash -sudo kill PID # SIGTERM (graceful shutdown, default) -sudo kill -9 PID # SIGKILL (force kill immediately) -sudo pkill -kill -u user # -kill = SIGKILL -``` - -## Competition Workflow - -### Active Defense Pattern - -1. **Someone monitors connections**: -```bash -# Run periodically or in a loop -sudo netstat -tunap -``` - -2. **Identify suspicious connections**: -- Unknown IP addresses -- Unexpected users logged in -- Unusual ports - -3. **Kill immediately**: -```bash -sudo pkill -kill -u -# or -sudo kill -``` - -4. **Someone else hardens the system**: -- Change passwords -- Disable accounts -- Configure firewall -- Close unnecessary services - -### Example Monitoring Script - -```bash -#!/bin/bash -# Quick connection checker -while true; do - clear - echo "=== Active SSH Connections ===" - sudo netstat -tunap | grep :22 | grep ESTABLISHED - sleep 5 -done -``` - -## Common Scenarios - -### Scenario 1: Unknown SSH Connection - -```bash -# See who's connected -w - -# Find their process ID -sudo netstat -tunap | grep ESTABLISHED - -# Kill by PID -sudo kill 265465 -``` - -### Scenario 2: Brute Force Attempts - -```bash -# See all connection attempts -sudo netstat -tunap | grep :22 - -# Check auth logs -sudo tail -f /var/log/auth.log - -# Block the source IP with firewall -sudo ufw deny from -``` - -### Scenario 3: Multiple Sessions from Same User - -```bash -# Kill all sessions for a user -sudo pkill -kill -u jenny - -# Disable the account -sudo passwd -l jenny # Lock password -sudo usermod -s /bin/false jenny # Disable shell -``` - -## Warnings and Gotchas - -### Don't Kill Yourself - -```bash -# BAD - if you're logged in as sandbox: -sudo pkill -kill -u sandbox -# This kills YOUR session too! -``` - -**Better approach**: Kill by specific PID if you're using the same username. - -### Don't Kill Teammates - -- Check with team before killing connections -- Look at FROM addresses to identify internal vs external -- Local (`:0`) connections are usually teammates at the console - -### Shared Accounts - -If red team is using the same account as you: -- Kill by PID (specific to their connection) -- Don't kill by username (you'll disconnect yourself) - -## Process Information Fields - -**Understanding PID in netstat**: -```bash -sudo netstat -tunap -``` - -Output: -``` -PID/Program name -265408/sshd: sandbox -265465/sshd: jenny -``` - -- PID: Process ID (unique number) -- Program: Which service (sshd, apache2, etc.) -- User context: Which user owns the process - -## Monitoring vs. Hardening - -**Active monitoring** (short-term): -- Running netstat/ss repeatedly -- Killing suspicious connections as they appear -- Playing "whack-a-mole" - -**Hardening** (long-term): -- Change passwords -- Disable unused accounts -- Configure firewall rules -- Close unnecessary services -- Update vulnerable software - -**Best practice**: Use monitoring to buy time while someone else hardens the system. You can't watch connections for 6 hours straight. - -## Tool Availability - -| Tool | Typical Availability | -|------|---------------------| -| netstat | Most systems (may need `net-tools` package) | -| ss | Modern systems (usually pre-installed) | -| w | All Unix/Linux systems | -| top | All Unix/Linux systems | -| htop | Optional (install with apt/yum) | -| ps | All Unix/Linux systems | - -**If netstat is missing**: -```bash -sudo apt install net-tools # Debian/Ubuntu -sudo yum install net-tools # CentOS/RHEL -``` - -Or just use `ss` instead. diff --git a/06-ufw-firewall.md b/07-ufw-firewall.md similarity index 100% rename from 06-ufw-firewall.md rename to 07-ufw-firewall.md diff --git a/08-active-connection-defense.md b/08-active-connection-defense.md new file mode 100644 index 0000000..a514b1a --- /dev/null +++ b/08-active-connection-defense.md @@ -0,0 +1,206 @@ +# Active Connection Defense + +Techniques for monitoring and terminating suspicious connections during competition. + +--- + +## View Active Connections + +### netstat Command + +Basic usage (too much output): +```bash +netstat +``` + +**Useful filtered version:** +```bash +netstat -tu # TCP and UDP connections only +netstat -tun # + resolve port numbers (shows 22 instead of "ssh") +netstat -tuna # + show listening ports too +sudo netstat -tunap # + show process IDs (requires sudo) +``` + +**Remember: `netstat -tunap`** (tuna + p) + +| Flag | Meaning | +|------|---------| +| `-t` | TCP connections | +| `-u` | UDP connections | +| `-n` | Show port numbers (not names) | +| `-a` | Show all (including listening) | +| `-p` | Show process IDs (requires sudo) | + +Example output: +``` +Proto Local Address Foreign Address State PID/Program +tcp 192.168.8.2:22 192.168.8.100:51736 ESTABLISHED 26546/sshd: jenny +tcp 192.168.8.2:22 192.168.8.100:51732 ESTABLISHED 26540/sshd: bob +``` + +### Filter with grep +```bash +sudo netstat -tunap | grep ESTABLISHED +sudo netstat -tunap | grep ssh +``` + +### ss Command (alternative to netstat) + +Some systems don't have netstat - use `ss` instead: +```bash +ss +ss -t # TCP only +ss | grep ESTABLISHED +``` + +--- + +## View Logged-In Users + +### w Command +```bash +w +``` + +Shows: +- Username +- TTY (terminal) +- From (IP address for remote, `:0` for local GUI) +- Login time +- What they're running + +Example output: +``` +USER TTY FROM LOGIN@ WHAT +sandbox :0 :0 09:00 /usr/bin/gnome-shell <- Local GUI +bob pts/1 192.168.8.100 10:15 -bash <- Remote SSH +jenny pts/2 192.168.8.100 10:16 -bash <- Remote SSH +``` + +**Note:** `:0` means local GUI session (probably your teammate), IP address means remote connection (possibly attacker). + +--- + +## Kill Connections + +### Kill by Process ID + +1. Find the PID with `netstat -tunap` +2. Kill it: +```bash +sudo kill +``` + +Example: +```bash +sudo netstat -tunap | grep ESTABLISHED +# See jenny's connection has PID 26546 +sudo kill 26546 +``` + +### Kill by Username + +Log out all sessions for a specific user: +```bash +sudo pkill -kill -u jenny +sudo pkill -kill -u bob +``` + +**⚠️ WARNING: Don't kill yourself!** +```bash +sudo pkill -kill -u sandbox # This kills YOUR session too! +``` + +If attacker is using the same account as you, kill by PID instead. + +--- + +## Monitor Processes + +### top Command +```bash +top # Live view of running processes +htop # Fancier version (may need to install) +``` + +Press `q` to quit. + +### ps Command +```bash +ps -aux # Show all processes with details +ps -aux | grep python # Find Python scripts +ps -aux | grep bash # Find bash scripts +``` + +Look for suspicious scripts running in background (attackers may leave these). + +--- + +## Send Messages to Users + +### Broadcast to All Users +```bash +wall "Server shutting down in 5 minutes. Please save your work." +``` + +All logged-in users see the message in their terminal. + +### Message Specific User +```bash +w # Find their TTY (e.g., pts/2) +sudo write bob pts/2 # Opens interactive message +# Type your message, Ctrl+C to end +``` + +--- + +## Competition Strategy + +### Active Defense Workflow + +1. **Monitor continuously:** + ```bash + sudo netstat -tunap | grep ESTABLISHED + w + ``` + +2. **Identify suspicious connections:** + - Unknown usernames + - Connections from unexpected IPs + - Multiple sessions from same IP + +3. **Kill suspicious connections:** + ```bash + sudo kill # By process ID + sudo pkill -kill -u # By username + ``` + +4. **Meanwhile, teammate secures server:** + - Change passwords + - Lock down user accounts + - Enable firewall + - Remove unnecessary services + +### Watch Out For + +- **Background scripts**: Attackers may leave Python/bash scripts running + ```bash + ps -aux | grep python + ps -aux | grep bash + ``` +- **Cron jobs**: Check `crontab -l` and `/etc/cron.*` +- **Friendly fire**: Don't kill your own sessions or teammates! + +--- + +## Quick Reference + +| Task | Command | +|------|---------| +| View connections | `sudo netstat -tunap` | +| View logged-in users | `w` | +| Kill by PID | `sudo kill ` | +| Kill by username | `sudo pkill -kill -u ` | +| View processes | `ps -aux` or `top` | +| Broadcast message | `wall "message"` | +| Message specific user | `sudo write ` | diff --git a/08-mikrotik-router.md b/09-mikrotik-router.md similarity index 100% rename from 08-mikrotik-router.md rename to 09-mikrotik-router.md