CactusCon 2014 CTF Writeup

This is a write up to the 2014 CactusCon web application (SpookiLeaks) challenge. You can grab the SpookiLeaks-VM here and try the challenge yourself before reading the solution.


The First Clue

The first clue to solving the challenge is hidden in plain sight. Before even logging in if we scan the pre-loaded images on the Spooky Images page there's one image with the ...

Postfix: Using Gmail as a Relay Host

I maintain several Linux servers at any given moment. Every server has postfix installed for sending emails, usually notifications or warning messages of some sort and most of these servers are professionally hosted allowing outbound emails with little to no configuration beyond installing postfix. However, my home server lies behind my ISP and they block all outbound emails citing SPAM as the reason. Regardless of their reasoning I had to find a workaround to allow me to send email notifications ...

Setting Up an Ubuntu Web Server

Having set up several Debian and Ubuntu web servers in the past I thought it would be a good idea to share my process. The following is a relatively comprehensive guide to installing and configuring an Apache based web server with some optimizations and basic resource monitoring. I primarily work with Ubuntu servers, but most of the commands here should work exactly the same in Debian or Ubuntu. I've tried to note where differences may occur.

Download and Install ...

Turn your old PC into a hardware firewall with IPCop

So you’ve got a 10-year old PC sitting around the house. You’re sick of your cats always getting into the wires and knocking the darn thing over. You don’t want to throw it away, but you just don’t know what to do with it. Well my friend, why don’t you turn that thing into a new hardware firewall?!

How would you go about doing that you might ask, well I’ve got the solution for ...

