Press Release: Hacker Playground

Security Lists <[email protected]> Mon, 5 Jul 2004 21:34:30 -0600 (MDT)
Newsgroups gmane.comp.security.events
Message-ID <[email protected]>
Well I sure hope this is the place to post this.

If not I am sorry for any inconvience I have caused.


-------------------------------------------------------------------


Hacker Playground (http://www.hackerplayground.com) is a new web site that 
will feature the Internet's FIRST legal private hackable network. This 
site has been developed in a response to the problems faced by security 
experts in the field with no way to test if their security models and 
skills can stand up against other security experts in the field. As a Unix 
Security Expert, Brian Carpio co-owner of hackerplayground.com, knows from 
first hand experience that with a live network it's hard to gain 
experience against new types of attacks. Test environments can be built, 
test servers can be setup, but who has the time to manage these test 
networks and test scenarios weekly? Most security engineers can test the 
security of their own network using tools such as nessus, sara, nmap, 
etc... but real experience is gained in the heat of an attack.

Hacker Playground also plan to address the issue of employers and 
recruiters finding qualified security experts, anyone can say they 
understand how to secure a Unix server but without having them setup a 
server and then finding other experts to try and exploit the server who 
really knows the level of these so-called security experts? Well Hacker 
Playground is going to offer a change for people to show off their skills 
with multiple Unix operating systems including Linux, Solaris, FreeBSD and 
more to come.

The games design is simple. Sign up for an account and gain access 
to a Fedora Core Linux box via ssh which has access to a private hackable 
network. The rules are quite simple root a server anyway possible sniff 
the network for passwords using arp posin attacks, run buffer overflows 
etc..., secure the server and leave three services open for others to try 
and take control away from you. The winner of the game will be determined 
by ?owned root time?, basically the user who owns root the longest wins 
the game!

Another interesting feature that the site designers have come up 
with is a way for the community to "Watch The Games". A monitor box 
running, p0f, ntop, snort, acid, nessus, nmap, and arpwatch is running 
ossim (http://www.ossim.net) as a web interface to bring all these monitor 
tools together into one simple interface to watch exactly what's going on 
behind the scenes. Nessus scan will be run daily to show the players and 
the community what's open and what's being secured. Snort will be logging 
all attacks run inside the network, and ntop will show who is logged into 
what box and how.

Hacker Playground has extensive plans for future growth including 
more boxes, vpn hacking, application hacking, quarterly tournaments in 
Denver, CO, white papers, data analysis of the games presented to the 
public for review and for purposes of learning what an attack can look 
like. Hacker Playground has plans to purchase servers which will support 
EVERY version of Linux they can get their hands on, NetBSD, OpenBSD, AIX, 
HPUX, and IRIX. They have plans on designing a VPN hackable network where 
again users will sign up for an account and then VPN into the hackable 
network which will allow them to use their own beefed up system to hack 
and secure boxes in the VPN hackable network. Finally quarterly ?HackOffs? 
will be hosted at their facility/warehouse tournaments style... more info 
will be found on their web site when it becomes available. White papers 
will be written by contestants of the games, the game owners Brian Carpio 
and Ben Sanson. Data from the games will be distributed back to the 
community for analysis and as a learning tool.


Finally Hacker Playground plans on offering services to the 
security community by testing new security applications on their hackable 
networks for vendors, testing new hack-prof devices on the hackable 
network and more...