❌

Reading view

Teaching network intrusion in the funnest way possible

I wanted to share a project I’ve been working on that I’m super excited about:

Project RedTeam: Contract Offensive

There’s a free Demo that provides a tutorial and lets you play a few contracts (no time limit, play as much as you want). Some players are already pulling some serious hours in the demo!

At its core, this is a game about using MITRE ATT&CK adversarial techniques against procedurally generated networks. It's delivered in a gameplay loop that plays a lot like Balatro and other card based Roguelike games. In Project RedTeam, you need to earn money to pay off debts after every contract within a run. Earn money by completing objectives, side bounties, or executing exfiltration/ransom against targets- the choice on how to be profitable is always yours.

It's a challenging but fun and fast paced take on network-intrusion cybersecurity concepts. It's entertaining in a deliberately gamified way.

A goal of this project was to create a hacking game that is realistic enough to keep it meaningful as a tool to teach intrusion concepts and stages to anyone- but not be overcomplicated and slow-paced like most hacking games.

I've put a lot of thought into the design and dynamics of how to capture the core-loop of network intrusion and turn it into a game that's approachable. The design direction of this project is an outcome of having over a decade of training and experience in cybersecurity.

Feel free to AMA! I'm happy to answer any questions about the game and/or development process :)

Give the game a Wishlist on Steam or share this post if it's something you support and want to see further development on.

Project background: This was implemented over the past 3 months using a modern development workflow (yes, modern AI tools make this possible- I'm not hiding that fact!). That being said, this is by far the most complex software project I've built as a solo developer and it was not an easy or simple development task. There's a Steam Community with a Dev Blog for this game that provides more history/progress updates on the project.

Mods: This will be my only and last post here, since it is promotional. I just wanted to share this since there’s been very positive interest from similar subreddits.

submitted by /u/ProjectRedTeam
[link] [comments]
  •  

SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click

I was going through the SelectorsHub code, id:ndgimibanhlabgdgjcpbbndiehljcpfh the XPath extension with about 400k users, and noticed it pulls ads from its own server and opens them in a background tab. You don't click anything.

Every couple of days the side panel pops up a "community link" and says "100% Safe, No Spam, No Malware." Five seconds later the tab opens by itself. The URL isn't in the extension. Their server picks it, and while I was analysing the extension the links changed three times with no extension update.

On install and update it skips the popup and just opens whatever the server sends.

The store page says they collect no data. The code still pings them daily, and the extension reads all your cookies to find one of its own instead of just fetching its own cookie value.

Another weird finding: there's a hidden Fix Selector button that sends the selector to shubads[.]testcasehub.net. VirusTotal - Domain - shubads.testcasehub.net
That host now redirects to a gambling site, blomehairdryers[.]com.

Nothing gets run today because the reply is HTML, but that's the server the eval path trusts.

Looks like adware, not password theft. I wouldn't leave it on a work browser, especially since this is a tool used by devs and tech people browsing protected endpoints in a company.

Write-up: https://malext.io/reports/RedirectorsHub/

submitted by /u/Huge-Skirt-6990
[link] [comments]
  •  
❌