|
[E] Attacker's IP Address
|
Traffic Analysis |
10 |
|
|
[E] Victim's IP Address
|
Traffic Analysis |
10 |
|
|
[M] Make Your Own Boarding Pass!
|
Boarding Pass Knowledge Checks |
100 |
|
|
[E] VHF vs HF
|
ACARS |
20 |
|
|
Info
|
Reverse Engineering Malware |
0 |
|
|
SURVEY
|
SURVEY |
100 |
|
|
ACARS Message Labels
|
ACARS |
0 |
|
|
[M] Topic
|
ARINC 853 Cabin Systems Pen-Test |
20 |
|
|
[M] IFE System
|
ARINC 853 Cabin Systems Pen-Test |
30 |
|
|
Cyber Attack 6
|
Become an Air Traffic Controller! |
75 |
|
|
Cyber Attack 4
|
Become an Air Traffic Controller! |
25 |
|
|
Cyber Attack 3
|
Become an Air Traffic Controller! |
100 |
|
|
[M] Bonus
|
ARINC 853 Cabin Systems Pen-Test |
80 |
|
|
[M] Logging
|
ARINC 853 Cabin Systems Pen-Test |
30 |
|
|
[E] MQTT Broker
|
ARINC 853 Cabin Systems Pen-Test |
10 |
|
|
[H] Database Attack
|
Flight Simulators |
200 |
|
|
[B] Something isn't right about that virtual link
|
Boeing - Medium |
30 |
|
|
[H] OS
|
Digital Boarding Pass |
10 |
|
|
[M] Attack
|
Artificial Intelligence |
150 |
|
|
[B] Source Constant Field that doesn't match the others?
|
Boeing - Medium |
30 |
|
|
[B] Find the virtual link (VL) identifier!
|
Boeing - Medium |
25 |
|
|
[M] Info
|
Remote ID |
0 |
|
|
[E] Publication
|
Remote ID |
10 |
|
|
[E] Regulatory Document
|
Remote ID |
10 |
|
|
[E] Drone Operation
|
Remote ID |
10 |
|
|
[E] FRIA
|
Remote ID |
10 |
|
|
[E] Compliance
|
Remote ID |
10 |
|
|
[E] UAS
|
Remote ID |
10 |
|
|
[E] Method
|
Remote ID |
10 |
|
|
[E] Same Info
|
Remote ID |
5 |
|
|
[E] Broadcast
|
Remote ID |
5 |
|
|
[B] Constant Sequence Numbers? WHAT?!
|
Boeing - Medium |
20 |
|
|
[B] TYPO AGAIN? sERIOUSLY?
|
Boeing - Easy |
15 |
|
|
[E] Log Analysis 2
|
RFID |
10 |
|
|
[E] Log Analysis 1
|
RFID |
10 |
|
|
Intro
|
Avionics Bus Tapping |
0 |
|
|
[E] This Is Your Operator Speaking
|
ATC Stego |
10 |
|
|
[E] Unlocked
|
ATC Stego |
10 |
|
|
[E] Puzzled
|
ATC Stego |
10 |
|
|
[DB] TRACON Navigation Assistance
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
50 |
|
|
[DB] TRACON ADS-B Spoofing
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
50 |
|
|
[B] Typo?
|
Boeing - Easy |
15 |
|
|
[M] Barcode?
|
Baggage Tag Knowledge Checks |
10 |
|
|
[M] What Is This IATA Airport Code?
|
Baggage Tag Knowledge Checks |
10 |
|
|
[M] IATA Airport Codes
|
Baggage Tag Knowledge Checks |
10 |
|
|
[M] Where Did It Go?
|
Baggage Tag Knowledge Checks |
10 |
|
|
[M] Where Did It Come From?
|
Baggage Tag Knowledge Checks |
10 |
|
|
[M] Priority?
|
Baggage Tag Knowledge Checks |
10 |
|
|
[B] Help my sequence is stuck!!!
|
Boeing - Easy |
15 |
|
|
[E] Hidden Flag
|
Boarding Pass Knowledge Checks |
10 |
|
|
[B] Name that Tool!
|
Boeing - Begin |
10 |
|
|
[B] START HERE FIRST
|
Boeing - Begin |
5 |
|
|
[RTX] 3 Pin Opaque Cylinder
|
RTX |
15 |
|
|
[E] Digital Boarding Pass
|
Boarding Pass Knowledge Checks |
10 |
|
|
[DB] XCD Flight Resilience
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
100 |
|
|
[DB] XCD Flight Performance
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
100 |
|
|
[DB] Diamond Aviation 62 #1
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
60 |
|
|
[DB] DA62 After Action #4
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
40 |
|
|
[DB] DA62 After Action #3
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
20 |
|
|
[DB] DA62 After Action #2
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
20 |
|
|
[DB] DA62 After Action #1
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
20 |
|
|
[DB] Diamond Aviation 62 #3
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
20 |
|
|
[DB] Diamond Aviation 62 #2
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
20 |
|
|
[E] Altitude
|
ADS-B Hacking |
10 |
|
|
[E] Aircraft Type 2
|
ADS-B Hacking |
10 |
|
|
[H] INJECT
|
ADS-B Hacking |
80 |
|
|
[H] Upgrade Attack 2
|
RFID |
70 |
|
|
[E] Attacking the Application Part 1
|
Restore FIDS |
10 |
|
|
[M] Enumerating the FIDS Part 5
|
Restore FIDS |
25 |
|
|
[E] Enumerating the FIDS Part 4
|
Restore FIDS |
10 |
|
|
[E] Enumerating the FIDS Part 3
|
Restore FIDS |
10 |
|
|
[E] Enumerating the FIDS Part 2
|
Restore FIDS |
10 |
|
|
[M] Upgrade Attack 1
|
RFID |
20 |
|
|
[E] Enumerating the FIDS Part 1
|
Restore FIDS |
10 |
|
|
Info
|
Remote ID |
0 |
|
|
Info
|
ACARS |
0 |
|
|
[RTX] Hollow Pad Lock
|
RTX |
40 |
|
|
[RTX] Handcuffs
|
RTX |
30 |
|
|
[M] Info
|
RFID |
0 |
|
|
[E] Wiegand Formatting 4
|
RFID |
10 |
|
|
[E] Wiegand Formatting 3
|
RFID |
10 |
|
|
[E] Wiegand Formatting 2
|
RFID |
10 |
|
|
[E] Wiegand Formatting 1
|
RFID |
10 |
|
|
[H] Final Flag
|
BBJA Web Privilege Escalation |
50 |
|
|
[M] File Path
|
BBJA Web Privilege Escalation |
25 |
|
|
[M] Secret
|
BBJA Web Privilege Escalation |
25 |
|
|
Info
|
Restore FIDS |
0 |
|
|
[H] Info
|
Digital Boarding Pass |
0 |
|
|
[M] Admin Email
|
BBJA Web Privilege Escalation |
25 |
|
|
[DB] King Air 200 #6
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
100 |
|
|
[DB] King Air 200 #5
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
150 |
|
|
[DB] King Air 200 #4
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
30 |
|
|
[DB] King Air 200 #3
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
60 |
|
|
[DB] King Air 200 #2
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
60 |
|
|
[DB] King Air 200 #1
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
20 |
|
|
[E] Aircraft Type
|
ADS-B Hacking |
10 |
|
|
[E] Registration
|
ADS-B Hacking |
10 |
|
|
[E] ICAO hex
|
ADS-B Hacking |
10 |
|
|
Disclaimer
|
ADS-B Hacking |
0 |
|
|
Intro
|
ADS-B Hacking |
0 |
|
|
[R] Attack the Drone
|
Riverside Research Mavlink |
50 |
|
|
[R] Mavlink Exploit
|
Riverside Research Mavlink |
20 |
|
|
[E] FTP
|
ARINC 853 Cabin Systems Pen-Test |
10 |
|
|
[E] Web Server
|
ARINC 853 Cabin Systems Pen-Test |
10 |
|
|
Info
|
RFID |
0 |
|
|
Info
|
Become an Air Traffic Controller! |
0 |
|
|
Info
|
ATC Stego |
0 |
|
|
[M] Info
|
Baggage Tag Knowledge Checks |
0 |
|
|
[E] Improving Security
|
Boarding Pass Knowledge Checks |
10 |
|
|
[DB] Cessna Citation XLS #5
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
40 |
|
|
[DB] Cessna Citation XLS #4
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
40 |
|
|
[DB] Cessna Citation XLS #3
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
40 |
|
|
[DB] Cessna Citation XLS #2
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
100 |
|
|
[E] Barcode Type
|
Boarding Pass Knowledge Checks |
10 |
|
|
[DB] Cessna Citation XLS #1
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
20 |
|
|
[E] Boarding Pass Standardization
|
Boarding Pass Knowledge Checks |
10 |
|
|
[E] What's issued?
|
Boarding Pass Knowledge Checks |
10 |
|
|
[E] Info
|
Boarding Pass Knowledge Checks |
0 |
|
|
Info
|
Boarding Pass/Baggage Tag |
0 |
|
|
Intro
|
Traffic Analysis |
0 |
|
|
Info
|
ARINC429 |
0 |
|
|
[R] Mavlink 20
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 19
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 18
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 17
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 16
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 15
|
Riverside Research Mavlink |
25 |
|
|
[M] Instrument Approach
|
Flight Simulators |
140 |
|
|
[R] Mavlink 14
|
Riverside Research Mavlink |
10 |
|
|
Intro
|
ARINC 853 Cabin Systems Pen-Test |
0 |
|
|
Info
|
Baggage Handling |
0 |
|
|
[R] Mavlink 13
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 12
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 11
|
Riverside Research Mavlink |
10 |
|
|
Info
|
BBJA Web Privilege Escalation |
0 |
|
|
[R] Mavlink 10
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 9
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 8
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 7
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 6
|
Riverside Research Mavlink |
10 |
|
|
[M] Storage
|
Artificial Intelligence |
20 |
|
|
[M] Enhanced
|
Artificial Intelligence |
20 |
|
|
[M] Understanding
|
Artificial Intelligence |
20 |
|
|
[E] How
|
Artificial Intelligence |
20 |
|
|
[E] Human Supervision
|
Artificial Intelligence |
20 |
|
|
[M] Technique
|
Artificial Intelligence |
10 |
|
|
[M] Atoms
|
Artificial Intelligence |
10 |
|
|
[M] Brain
|
Artificial Intelligence |
10 |
|
|
[E] Profile
|
Artificial Intelligence |
10 |
|
|
[R] Mavlink 5
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 4
|
Riverside Research Mavlink |
10 |
|
|
[E] Stakeholder Involvement
|
Artificial Intelligence |
10 |
|
|
[E] Literature Review
|
Artificial Intelligence |
10 |
|
|
[R] TLS Exploit
|
Riverside Research TLS/Heartbleed |
40 |
|
|
[E] Core
|
Artificial Intelligence |
10 |
|
|
[E] Risk Management
|
Artificial Intelligence |
10 |
|
|
[E] Document ID
|
Artificial Intelligence |
10 |
|
|
[E] Accountability
|
Artificial Intelligence |
10 |
|
|
[M] Info
|
Artificial Intelligence |
0 |
|
|
Info
|
Artificial Intelligence |
0 |
|
|
[H] Discovering the enabled policy
|
Airport Kiosk Privilege Escalation |
50 |
|
|
[H] Disable all restrictive controls for free access to all applications
|
Airport Kiosk Privilege Escalation |
100 |
|
|
[R] Mavlink 3
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 2
|
Riverside Research Mavlink |
10 |
|
|
[R] Mavlink 1
|
Riverside Research Mavlink |
10 |
|
|
[R] Intro to Mavlink
|
Riverside Research Mavlink |
10 |
|
|
[DB] Info
|
CARS Flight Deck Equipment Bench Cyber Challenge [ERAU Daytona Beach] |
0 |
|
|
[R] TLS 10
|
Riverside Research TLS/Heartbleed |
25 |
|
|
[M] Landing Challenge
|
Flight Simulators |
100 |
|
|
[R] TLS 9
|
Riverside Research TLS/Heartbleed |
20 |
|
|
[H] Info
|
Airport Ground Vehicle Manipulation |
0 |
|
|
Intro
|
ACARS |
0 |
|
|
[R] TLS 8
|
Riverside Research TLS/Heartbleed |
20 |
|
|
[R] TLS 7
|
Riverside Research TLS/Heartbleed |
30 |
|
|
[R] TLS 6
|
Riverside Research TLS/Heartbleed |
20 |
|
|
[E] First Flight!
|
Flight Simulators |
70 |
|
|
[H] Gain command prompt access over the system
|
Airport Kiosk Privilege Escalation |
150 |
|
|
[R] TLS 5
|
Riverside Research TLS/Heartbleed |
20 |
|
|
Info
|
ARINC 853 Cabin Systems Pen-Test |
0 |
|
|
[A] Info
|
A429 Challenge [AIRBUS] |
0 |
|
|
Intro
|
ARINC429 |
0 |
|
|
Intro
|
Flight Simulators |
0 |
|
|
[E] Find your allowed applications in Explorer
|
Airport Kiosk Privilege Escalation |
10 |
|
|
[R] TLS 4
|
Riverside Research TLS/Heartbleed |
10 |
|
|
[R] TLS 3
|
Riverside Research TLS/Heartbleed |
10 |
|
|
[E] Find Powershell in the Explorer
|
Airport Kiosk Privilege Escalation |
10 |
|
|
[R] TLS 2
|
Riverside Research TLS/Heartbleed |
10 |
|
|
[R] TLS 1
|
Riverside Research TLS/Heartbleed |
10 |
|
|
[R] Intro to TLS Hacking
|
Riverside Research TLS/Heartbleed |
10 |
|
|
[R] Intro to TLS/Heartbleed
|
Riverside Research TLS/Heartbleed |
10 |
|
|
[R] Info
|
Riverside Research TLS/Heartbleed |
0 |
|
|
[R] Info
|
Riverside Research Mavlink |
0 |
|
|
Info
|
Airport Kiosk Privilege Escalation |
0 |
|