Flag Bearer

Details

While at ISEAGE, I developed a small program to help new competitors correctly place their flags, as well as provide a convenient tool for experienced competitors and Red Teamers. This tool interacts with the IScorE API in order to get the list of flags for the current user and provides the ability to automatically place them.

After graduating and starting red teaming, I created the Red Team version of Flag Bearer: Flag Slurper. While it incorporates the functionality of Flag Bearer, it is aimed at Red Team.

The primary (and most fun) feature is the ability to grab a list of teams and their services, and check default usernames and passwords against as many of the team’s services as it can. While doing so, it will attempt to find flags on the system and report them back. It is also envisioned as a way for Red Team to share information about teams in an easy way.

Demo