Course data files
Everything the labs need, in one place. Nothing here requires a virtual machine or a server. Apart from installing cryptography once and opening Compiler Explorer for vuln.c, nothing needs an internet connection. Download the file the lab names, run it or read it, and go.
| File | Used by | What it is |
|---|---|---|
| SnapVault system description | Lab 2, Lab 3 | A written description of "SnapVault", a small photo-sharing service. You threat-model it. |
| NORTHWIND MEADOW incident report | Lab 7 | The NORTHWIND MEADOW post-incident write-up. You classify the malware and map it to MITRE ATT&CK. |
| password_demo.py | Week 5 module, D3 | Fast hashing vs. slow hashing vs. salting, with timings you can measure. |
| crypto_demo.py | Lab 4 | ECB vs. CTR on a picture, integrity with and without GCM, and nonce reuse. |
| sign_demo.py | Lab 5 | Hash avalanche, Ed25519 signing and verification, MAC vs. signature. |
| cert_inspect.py | Lab 6 | Builds a certificate chain and runs the checks a browser runs on three server certificates. |
| vuln.c | Lab 8 | A badge reader with a stack buffer overflow. You read it; you never run it. |
| sqli_demo.py | Lab 9 | A login form built two ways: string concatenation and parameterized queries. |
| auth.log | Lab 10 | 548 lines of SSH authentication log from a server called vault-api-01. |
| web_access.log | Lab 10 | 318 lines of web server access log in Apache combined format. |
Running the Python scripts
Five of the files are Python programs. Two of them use only the standard library and will run on any Python 3.11 or newer:
python3 password_demo.py
python3 sqli_demo.pyThree of them need the cryptography package, which you install once in Lab 0:
pip install cryptography
python3 crypto_demo.py
python3 sign_demo.py
python3 cert_inspect.pyEvery script has a block near the top marked CHANGE THESE. Those are the values the lab asks you to experiment with. You never need to modify anything below that block, and you never need to write a program from scratch in this course.
crypto_demo.py writes three .bmp image files into whatever directory you run it from. Every other script only prints to the screen.
Provenance
These files were written for CS 331. They are not real data:
- SnapVault is a fictional company. Its architecture is assembled from patterns that are common in small production services, including the mistakes.
- NORTHWIND MEADOW is a fictional incident at a fictional hospital network. Its shape (phishing to macro to fileless loader, a week of living-off-the-land lateral movement, exfiltration, then ransomware) follows patterns from published incident reporting, but no real organization, person, or campaign is described. The domains in it are written with
[.]so they cannot be clicked. They were not registered when the report was written, but that can change, so do not visit them. auth.logandweb_access.logare synthetic, generated to contain specific patterns that Lab 10 asks you to find. The IP addresses are all from ranges reserved for documentation (RFC 5737:192.0.2.0/24,198.51.100.0/24,203.0.113.0/24) plus private addresses, so none of them belongs to a real host anywhere.vuln.cis written to be read, not run. The bug in it is the textbook one.- The certificates in
cert_inspect.pyare generated fresh every time you run it and are signed by a root that exists only inside that one process. They are not trusted by anything.
Nothing in this directory attacks a system you do not own, and nothing here needs a network.