<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=KSzepannek</id>
	<title>Elvis Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://elvis.hcw.ac.at/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=KSzepannek"/>
	<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php/Special:Contributions/KSzepannek"/>
	<updated>2026-09-10T16:31:59Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.41.5</generator>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=OverTheWire_CTF_Wargames&amp;diff=17699</id>
		<title>OverTheWire CTF Wargames</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=OverTheWire_CTF_Wargames&amp;diff=17699"/>
		<updated>2024-12-18T21:17:24Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The community-based project OverTheWire offers Capture-The-Flag (CTF) wargames for IT-Security enthusiasts and learners. The wargames all focus on different aspects of IT-security or computer sciences like for example Linux systems, cryptography or serverside web application security. The official website OverTheWire.org lists 13 available wargames as of december 2024, with only one of them being available for offline use. The other 12 games are accessed via either SSH or in the case of the serverside web application security focused wargame “Natas” , via a web browser and other tools. As usual for CTF Games in IT-Security, the goal of each level in the wargames is to obtain the password for entering the next one, in this case for accessing the SSH user. The website offers little guidance to beat the challenges posed by the wargames but being around for much over 10 years, a lot of blog entries and YouTube walkthroughs on the wargames have emerged.&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
This documentation will help to get started with solving the OverTheWire wargames.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Any, that can run a SSH Shell.&lt;br /&gt;
* SSH Shell: For example Putty on Windows or Unix based operating systems.&lt;br /&gt;
* Packages: Additional Packages may be required for some wargames.&lt;br /&gt;
&lt;br /&gt;
== General Tips ==&lt;br /&gt;
&lt;br /&gt;
To connect to a SSH wargame you will find the SSH hostname and port on each games own site. If you are connecting with Putty you may find it helpful to save the hostname and port in a session like seen in the picture below, for the wargame Bandit:&lt;br /&gt;
[[file:putty_stored_session.png]]&lt;br /&gt;
&lt;br /&gt;
This is useful because after completing the challenge you may have to close the session and enter again.&lt;br /&gt;
&lt;br /&gt;
Also, save the passwords (captured flags) you have obtained because if you loose the current one you will have to start again! The passwords change from time to time so you probably also won&#039;t find them online.&lt;br /&gt;
&lt;br /&gt;
== Bandit ==&lt;br /&gt;
&lt;br /&gt;
Bandit is the easiest wargame and the first one in the suggested order to play them. It is about basic Linux filesystems. You may find it helpful to first read the following [https://manpages.ubuntu.com/manpages/noble/man1/intro.1.html manpage] if you have never worked with a Linux machine before (highly unlikely i know).&lt;br /&gt;
&lt;br /&gt;
To connect to the Bandit Wargame use the following hostname and port:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Level 0 ===&lt;br /&gt;
&lt;br /&gt;
Login as bandit0 with password bandit0.&lt;br /&gt;
&lt;br /&gt;
[[file:Bandit_Login2.png]]&lt;br /&gt;
&lt;br /&gt;
Then try the &amp;quot;ls&amp;quot; command to list all files and directories. To read a file use the &amp;quot;cat&amp;quot; command.&lt;br /&gt;
&lt;br /&gt;
[[file:Bandit_Level0.png]]&lt;br /&gt;
&lt;br /&gt;
The password is found in the read file &amp;quot;readme&amp;quot;.&lt;br /&gt;
=== Level 1 ===&lt;br /&gt;
&lt;br /&gt;
Login as bandit1 with the password from the level 1.&lt;br /&gt;
&lt;br /&gt;
Try entering the command &amp;quot;ls&amp;quot; and then to read the strangely named file &amp;quot;-&amp;quot; you will find. As you will see, you can&#039;t read it by simply typing its name. Use &amp;quot;./&amp;quot; before the filename now.&lt;br /&gt;
&lt;br /&gt;
[[file:Bandit_Level1.png]]&lt;br /&gt;
&lt;br /&gt;
=== Level 2 ===&lt;br /&gt;
&lt;br /&gt;
Login as bandit2 with the password from the level 2.&lt;br /&gt;
&lt;br /&gt;
For this wargame try putting the filename in brackets.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Level 3 ===&lt;br /&gt;
&lt;br /&gt;
Login as bandit3 with the password from the level 3.&lt;br /&gt;
&lt;br /&gt;
Use &amp;quot;ls&amp;quot; to find the directory. You can move to the directory with the cd command.&lt;br /&gt;
&lt;br /&gt;
Try to find the file containing the password&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://OverTheWire.org&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Bandit_Level1.png&amp;diff=17696</id>
		<title>File:Bandit Level1.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Bandit_Level1.png&amp;diff=17696"/>
		<updated>2024-12-18T20:59:15Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Bandit_Level0.png&amp;diff=17695</id>
		<title>File:Bandit Level0.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Bandit_Level0.png&amp;diff=17695"/>
		<updated>2024-12-18T20:58:52Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Bandit_Login2.png&amp;diff=17694</id>
		<title>File:Bandit Login2.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Bandit_Login2.png&amp;diff=17694"/>
		<updated>2024-12-18T20:58:31Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Bandit_Login.png&amp;diff=17693</id>
		<title>File:Bandit Login.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Bandit_Login.png&amp;diff=17693"/>
		<updated>2024-12-18T20:58:00Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=File:Putty_stored_session.png&amp;diff=17692</id>
		<title>File:Putty stored session.png</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=File:Putty_stored_session.png&amp;diff=17692"/>
		<updated>2024-12-18T20:57:16Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=OverTheWire_CTF_Wargames&amp;diff=17690</id>
		<title>OverTheWire CTF Wargames</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=OverTheWire_CTF_Wargames&amp;diff=17690"/>
		<updated>2024-12-18T20:55:32Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The community-based project OverTheWire offers Capture-The-Flag (CTF) wargames for IT-Security enthusiasts and learners. The wargames all focus on different aspects of IT-security or computer sciences like for example Linux systems, cryptography or serverside web application security. The official website OverTheWire.org lists 13 available wargames as of december 2024, with only one of them being available for offline use. The other 12 games are accessed via either SSH or in the case of the serverside web application security focused wargame “Natas” , via a web browser and other tools. As usual for CTF Games in IT-Security, the goal of each level in the wargames is to obtain the password for entering the next one, in this case for accessing the SSH user. The website offers little guidance to beat the challenges posed by the wargames but being around for much over 10 years, a lot of blog entries and YouTube walkthroughs on the wargames have emerged.&lt;br /&gt;
&lt;br /&gt;
== Summary ==&lt;br /&gt;
&lt;br /&gt;
This documentation will help to get started with solving the OverTheWire wargames.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Any, that can run a SSH Shell.&lt;br /&gt;
* SSH Shell: For example Putty on Windows or Unix based operating systems.&lt;br /&gt;
* Packages: Additional Packages may be required for some wargames.&lt;br /&gt;
&lt;br /&gt;
== General Tips ==&lt;br /&gt;
&lt;br /&gt;
To connect to a SSH wargame you will find the SSH hostname and port on each games own site. If you are connecting with Putty you may find it helpful to save the hostname and port in a session like seen in the picture below, for the wargame Bandit:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This is useful because after completing the challenge you may have to close the session and enter again.&lt;br /&gt;
&lt;br /&gt;
Also, save the passwords (captured flags) you have obtained because if you loose the current one you will have to start again. The passwords change from time to time so you probably also won&#039;t find them online.&lt;br /&gt;
&lt;br /&gt;
== Bandit ==&lt;br /&gt;
&lt;br /&gt;
This wargame is about basic Linux filesystems. You may find it helpful to first read the following [https://manpages.ubuntu.com/manpages/noble/man1/intro.1.html manpage].&lt;br /&gt;
&lt;br /&gt;
To connect to the Bandit Wargame use the following hostname and port:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Level 0 ===&lt;br /&gt;
&lt;br /&gt;
Login as bandit0 with password bandit0.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Level 1 ===&lt;br /&gt;
&lt;br /&gt;
Login as bandit1 with the password from the level 1.&lt;br /&gt;
&lt;br /&gt;
=== Level 2 ===&lt;br /&gt;
&lt;br /&gt;
Login as bandit2 with the password from the level 2.&lt;br /&gt;
&lt;br /&gt;
=== Level 3 ===&lt;br /&gt;
&lt;br /&gt;
Login as bandit3 with the password from the level 3.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://OverTheWire.org&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=OWASP_Top_10&amp;diff=17641</id>
		<title>OWASP Top 10</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=OWASP_Top_10&amp;diff=17641"/>
		<updated>2024-12-18T19:50:44Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The OWASP Top 10 is a globally recognized standard that identifies the ten most critical security risks to web applications. Published by the Open Web Application Security Project (OWASP), a non-profit organization dedicated to improving software security, the OWASP Top 10 serves as an important resource for developers, security professionals, and organizations aiming to secure web applications and protect sensitive data from attacks.&lt;br /&gt;
== Purpose and Objectives ==&lt;br /&gt;
The primary goal of the OWASP Top 10 is to raise awareness of web application security vulnerabilities and provide guidance for mitigating these risks. By highlighting the most common and impactful threats, the list helps developers to write secure code, security teams to focus on critical areas and organisations to integrate those practices into their development.&lt;br /&gt;
&lt;br /&gt;
The OWASP Top 10 not only serves as an educational resource but also as a benchmark for compliance standards and as a good foundation for secure coding policies in enterprises. Its purpose is to help collaboration between development and security teams, ensuring that security becomes an integral part of the software development process.&lt;br /&gt;
By providing detailed explanations, real-world examples, and guidance, the OWASP Top 10 helps organizations to understand security risks and implement measures to prevent them. &lt;br /&gt;
== History and Evolution ==&lt;br /&gt;
&lt;br /&gt;
=== Formation and Early Development ===&lt;br /&gt;
The OWASP Top 10 was first published in 2003 by the OWASP Foundation, which was founded by Mark Curphey and a team of volunteers. The original list was created to address the growing need for standardized guidance on web application security, as the internet became more connected to business operations. At the time, awareness of web application vulnerabilities was low, and there were only a few resources available for developers and security professionals to learn about them.&lt;br /&gt;
The OWASP Foundation was established with the mission of creating free and open resources for improving application security. The Top 10 list quickly became one of its flagship projects, gaining widespread adoption due to its format and practical advice.&lt;br /&gt;
&lt;br /&gt;
=== Evolution of Methods ===&lt;br /&gt;
The methods used to create the OWASP Top 10 have improved a lot over the years to make them more accurate and fair. Earlier versions focused on a small set of known vulnerabilities and relied heavily on expert opinions. In 2017, OWASP introduced a more structured process, using incidence rates to measure how many applications had at least one instance of a vulnerability. This approach gave a clearer picture of risks across many applications, rather than just counting the number of issues found. By 2021, the process expanded to analyze nearly 400 vulnerabilities (CWEs) and included scores for how easy vulnerabilities were to exploit and their impact. Community surveys were also added to capture new threats and insights from security experts. These changes have made the OWASP Top 10 a strong and reliable guide for dealing with modern security risks.&lt;br /&gt;
=== Major Updates Over the Years ===&lt;br /&gt;
The OWASP Top 10 has had many updates to reflect changing threats and technologies and shifts in attacker behavior. Each update has been built on feedback from security practitioners, data from real-world breach reports, and insights from academic research. Key updates include:&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2003&#039;&#039;&#039;: The first list identified issues like &amp;quot;Buffer Overflows,&amp;quot; &amp;quot;Cross-Site Scripting (XSS),&amp;quot; and &amp;quot;SQL Injection.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2007&#039;&#039;&#039;: This update had a more structured approach to categorize risks and included vulnerabilities like &amp;quot;Insecure Communications&amp;quot; and &amp;quot;Failure to Restrict URL Access.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2010&#039;&#039;&#039;: As web applications became more complex, the 2010 version focused on risks like &amp;quot;Security Misconfiguration&amp;quot; and &amp;quot;Insufficient Transport Layer Protection.&amp;quot; This edition also highlighted the importance of secure session management.&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2013&#039;&#039;&#039;: This update reflected a growing dependence on third-party components and added a category &amp;quot;Using Components with Known Vulnerabilities&amp;quot; but also authentication and authorization issues.&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2017&#039;&#039;&#039;: The 2017 list introduced modern risks like &amp;quot;XML External Entities (XXE)&amp;quot; and &amp;quot;Insufficient Logging and Monitoring.&amp;quot; The addition of these categories reflected trends such as the rise of APIs and the importance of detecting attacks in real time.&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2021&#039;&#039;&#039;: The most recent update prioritized risks like &amp;quot;Insecure Design&amp;quot; and &amp;quot;Software and Data Integrity Failures.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Each iteration of the OWASP Top 10 comes with detailed documentation, including explanations of the methods used to compile the list, descriptions of each risk, and recommended mitigation strategies.&lt;br /&gt;
&lt;br /&gt;
== OWASP Top 10 Categories ==&lt;br /&gt;
&lt;br /&gt;
An OWASP Top 10 category is made up of a group of related vulnerabilities (CWEs) that share a common root cause or theme. Each category focuses on the underlying issue, such as &amp;quot;Cryptographic Failures&amp;quot; or &amp;quot;Misconfigurations,&amp;quot; rather than just the symptoms like &amp;quot;Sensitive Data Exposure.&amp;quot; On average, a category includes about 19 CWEs, though some have as few as one (like Server-Side Request Forgery) or as many as 40 (like Insecure Design). Categories are also ranked based on factors like how often vulnerabilities occur in real-world applications, how easy they are to exploit, and the impact they can have if exploited. This structure helps developers and organizations focus on fixing the core problems that lead to security issues.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://owasp.org&lt;br /&gt;
* https://owasp.org/top10&lt;br /&gt;
* https://owasp.org/www-project-top-ten/2017/&lt;br /&gt;
* https://owasp.org/Top10/A00_2021_Introduction/&lt;br /&gt;
* https://github.com/OWASP/Top10/blob/master/2017-2003_Comparison/OWASP_Top_Ten_-_Comparison_of_2003%2C2004%2C2007%2C2010%2C2013_and_2017_Releases.docx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=OWASP_Top_10&amp;diff=17527</id>
		<title>OWASP Top 10</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=OWASP_Top_10&amp;diff=17527"/>
		<updated>2024-12-18T17:17:28Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The OWASP Top 10 is a globally recognized standard that identifies the ten most critical security risks to web applications. Published by the Open Web Application Security Project (OWASP), a non-profit organization dedicated to improving software security, the OWASP Top 10 serves as an important resource for developers, security professionals, and organizations aiming to secure web applications and protect sensitive data from attacks.&lt;br /&gt;
== Purpose and Objectives ==&lt;br /&gt;
The primary goal of the OWASP Top 10 is to raise awareness of web application security vulnerabilities and provide guidance for mitigating these risks. By highlighting the most common and impactful threats, the list helps developers to write secure code, security teams to focus on critical areas and organisations to integrate those practices into their development.&lt;br /&gt;
&lt;br /&gt;
The OWASP Top 10 not only serves as an educational resource but also as a benchmark for compliance standards and as a good foundation for secure coding policies in enterprises. Its purpose is to help collaboration between development and security teams, ensuring that security becomes an integral part of the software development process.&lt;br /&gt;
By providing detailed explanations, real-world examples, and guidance, the OWASP Top 10 helps organizations to understand security risks and implement measures to prevent them. &lt;br /&gt;
== History and Evolution ==&lt;br /&gt;
=== Formation and Early Development ===&lt;br /&gt;
The OWASP Top 10 was first published in 2003 by the OWASP Foundation, which was founded by Mark Curphey and a team of volunteers. The original list was created to address the growing need for standardized guidance on web application security, as the internet became more connected to business operations. At the time, awareness of web application vulnerabilities was low, and there were only a few resources available for developers and security professionals to learn about them.&lt;br /&gt;
The OWASP Foundation was established with the mission of creating free and open resources for improving application security. The Top 10 list quickly became one of its flagship projects, gaining widespread adoption due to its format and practical advice.&lt;br /&gt;
=== Major Updates Over the Years ===&lt;br /&gt;
The OWASP Top 10 has had many updates to reflect changing threats and technologies and shifts in attacker behavior. Each update has been built on feedback from security practitioners, data from real-world breach reports, and insights from academic research. Key updates include:&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2003&#039;&#039;&#039;: The first list identified issues like &amp;quot;Buffer Overflows,&amp;quot; &amp;quot;Cross-Site Scripting (XSS),&amp;quot; and &amp;quot;SQL Injection.&amp;quot; &lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2007&#039;&#039;&#039;: This update had a more structured approach to categorize risks and included vulnerabilities like &amp;quot;Insecure Communications&amp;quot; and &amp;quot;Failure to Restrict URL Access.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2010&#039;&#039;&#039;: As web applications became more complex, the 2010 version focused on risks like &amp;quot;Security Misconfiguration&amp;quot; and &amp;quot;Insufficient Transport Layer Protection.&amp;quot; This edition also highlighted the importance of secure session management.&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2013&#039;&#039;&#039;: This update reflected a growing dependence on third-party components and added a category &amp;quot;Using Components with Known Vulnerabilities&amp;quot; but also authentication and authorization issues.&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2017&#039;&#039;&#039;: The 2017 list introduced modern risks like &amp;quot;XML External Entities (XXE)&amp;quot; and &amp;quot;Insufficient Logging and Monitoring.&amp;quot; The addition of these categories reflected trends such as the rise of APIs and the importance of detecting attacks in real time.&lt;br /&gt;
&lt;br /&gt;
•	&#039;&#039;&#039;2021&#039;&#039;&#039;: The most recent update prioritized risks like &amp;quot;Insecure Design&amp;quot; and &amp;quot;Software and Data Integrity Failures.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Each iteration of the OWASP Top 10 comes with detailed documentation, including explanations of the methods used to compile the list, descriptions of each risk, and recommended mitigation strategies.&lt;br /&gt;
&lt;br /&gt;
== Description of the Categories ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
+++&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://owasp.org&lt;br /&gt;
* https://owasp.org/top10&lt;br /&gt;
* https://owasp.org/www-project-top-ten/2017/&lt;br /&gt;
* https://github.com/OWASP/Top10/blob/master/2017-2003_Comparison/OWASP_Top_Ten_-_Comparison_of_2003%2C2004%2C2007%2C2010%2C2013_and_2017_Releases.docx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=OWASP_Top_10&amp;diff=17372</id>
		<title>OWASP Top 10</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=OWASP_Top_10&amp;diff=17372"/>
		<updated>2024-12-18T14:58:58Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: Initial Creation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
OWASP and OWASP Top 10&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Ubuntu 18.04 bionic amd64&lt;br /&gt;
* Packages: git emacs&lt;br /&gt;
&lt;br /&gt;
In order to complete these steps, you must have followed [[Some Other Documentation]] before.&lt;br /&gt;
&lt;br /&gt;
== Description ==&lt;br /&gt;
&lt;br /&gt;
=== Step 1 ===&lt;br /&gt;
&lt;br /&gt;
Enter these commands in the shell&lt;br /&gt;
&lt;br /&gt;
 echo foo&lt;br /&gt;
 echo bar&lt;br /&gt;
&lt;br /&gt;
=== Step 2 ===&lt;br /&gt;
&lt;br /&gt;
Make sure to read&lt;br /&gt;
&lt;br /&gt;
* War and Peace&lt;br /&gt;
* Lord of the Rings&lt;br /&gt;
* The Baroque Cycle&lt;br /&gt;
&lt;br /&gt;
== Used Hardware ==&lt;br /&gt;
&lt;br /&gt;
[[Device to be used with this documentation]]&lt;br /&gt;
[[Maybe another device to be used with this documentation]]&lt;br /&gt;
&lt;br /&gt;
== Courses ==&lt;br /&gt;
&lt;br /&gt;
* [[A course where this documentation was used]] (2017, 2018)&lt;br /&gt;
* [[Another one]] (2018)&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://wikipedia.org&lt;br /&gt;
* https://google.com&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
	<entry>
		<id>https://elvis.hcw.ac.at/wiki/index.php?title=OverTheWire_CTF_Wargames&amp;diff=17353</id>
		<title>OverTheWire CTF Wargames</title>
		<link rel="alternate" type="text/html" href="https://elvis.hcw.ac.at/wiki/index.php?title=OverTheWire_CTF_Wargames&amp;diff=17353"/>
		<updated>2024-12-18T12:20:12Z</updated>

		<summary type="html">&lt;p&gt;KSzepannek: Created page with &amp;quot;== Summary ==   The community-based project OverTheWire offers Capture-The-Flag (CTF) wargames for IT-Security enthusiasts and learners. The wargames all focus on different aspects of IT-security or computer sciences like for example Linux systems, cryptography or serverside web application security. The official website OverTheWire.org lists 13 available wargames as of december 2024, with only one of them being available for offline use. The other 12 games are accessed...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Summary == &lt;br /&gt;
&lt;br /&gt;
The community-based project OverTheWire offers Capture-The-Flag (CTF) wargames for IT-Security enthusiasts and learners. The wargames all focus on different aspects of IT-security or computer sciences like for example Linux systems, cryptography or serverside web application security. The official website OverTheWire.org lists 13 available wargames as of december 2024, with only one of them being available for offline use. The other 12 games are accessed via either SSH or in the case of the serverside web application security focused wargame “Natas” , via a web browser and other tools. As usual for CTF Games in IT-Security, the goal of each level in the wargames is to obtain the password for entering the next one, in this case for accessing the SSH user. The website offers little guidance to beat the challenges posed by the wargames but being around for much over 10 years, a lot of blog entries and YouTube walkthroughs on the wargames have emerged.&lt;br /&gt;
&lt;br /&gt;
== Requirements ==&lt;br /&gt;
&lt;br /&gt;
* Operating system: Any, that can run a SSH Shell.&lt;br /&gt;
* SSH Shell: For example Putty on Windows or Unix based operating systems.&lt;br /&gt;
* Packages: Additional Packages may be required for some wargames.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&lt;br /&gt;
* https://OverTheWire.org&lt;br /&gt;
&lt;br /&gt;
[[Category:Documentation]]&lt;/div&gt;</summary>
		<author><name>KSzepannek</name></author>
	</entry>
</feed>