4 Hours+FinalCall0VulnerabilitiesWeb APPhas a(good)FirewallEnvironmentis brokenXSS withAdminBot20+CritsFormatStringInjectionRCE Exploitworks onmultipleHosts0TechnicalCustomersWrongIPs/HostsprovidedOnly 1VPNconnection0 CustomerResponsesduring theTestDefaultCredentialsUnauthorizedFTPOutdatedSoftwarewith knownvulnsCommandInjectionUnauthorizedSMBSSRFYour testmachinecrashesAccess toExampleReportsUnauthorizedDatabaseUnauthorizedDoS FeatureSQLInjectionUnauthorizedNFS4 Hours+FinalCall0VulnerabilitiesWeb APPhas a(good)FirewallEnvironmentis brokenXSS withAdminBot20+CritsFormatStringInjectionRCE Exploitworks onmultipleHosts0TechnicalCustomersWrongIPs/HostsprovidedOnly 1VPNconnection0 CustomerResponsesduring theTestDefaultCredentialsUnauthorizedFTPOutdatedSoftwarewith knownvulnsCommandInjectionUnauthorizedSMBSSRFYour testmachinecrashesAccess toExampleReportsUnauthorizedDatabaseUnauthorizedDoS FeatureSQLInjectionUnauthorizedNFS

BINGO!!! - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. 4 Hours+ Final Call
  2. 0 Vulnerabilities
  3. Web APP has a (good) Firewall
  4. Environment is broken
  5. XSS with Admin Bot
  6. 20+ Crits
  7. Format String Injection
  8. RCE Exploit works on multiple Hosts
  9. 0 Technical Customers
  10. Wrong IPs/Hosts provided
  11. Only 1 VPN connection
  12. 0 Customer Responses during the Test
  13. Default Credentials
  14. Unauthorized FTP
  15. Outdated Software with known vulns
  16. Command Injection
  17. Unauthorized SMB
  18. SSRF
  19. Your test machine crashes
  20. Access to Example Reports
  21. Unauthorized Database
  22. Unauthorized DoS Feature
  23. SQL Injection
  24. Unauthorized NFS