Command Injection 0 Technical Customers SQL Injection SSRF 4 Hours+ Final Call 20+ Crits Unauthorized Database Your test machine crashes Unauthorized DoS Feature Outdated Software with known vulns Web APP has a (good) Firewall Only 1 VPN connection Unauthorized FTP 0 Customer Responses during the Test Wrong IPs/Hosts provided Unauthorized SMB 0 Vulnerabilities XSS with Admin Bot Access to Example Reports Format String Injection Unauthorized NFS RCE Exploit works on multiple Hosts Default Credentials Environment is broken Command Injection 0 Technical Customers SQL Injection SSRF 4 Hours+ Final Call 20+ Crits Unauthorized Database Your test machine crashes Unauthorized DoS Feature Outdated Software with known vulns Web APP has a (good) Firewall Only 1 VPN connection Unauthorized FTP 0 Customer Responses during the Test Wrong IPs/Hosts provided Unauthorized SMB 0 Vulnerabilities XSS with Admin Bot Access to Example Reports Format String Injection Unauthorized NFS RCE Exploit works on multiple Hosts Default Credentials Environment is broken
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Command Injection
0 Technical Customers
SQL Injection
SSRF
4 Hours+ Final Call
20+ Crits
Unauthorized Database
Your test machine crashes
Unauthorized
DoS Feature
Outdated Software with known vulns
Web APP has a (good) Firewall
Only 1 VPN connection
Unauthorized FTP
0 Customer Responses during the Test
Wrong IPs/Hosts provided
Unauthorized SMB
0 Vulnerabilities
XSS with Admin Bot
Access to Example Reports
Format String Injection
Unauthorized NFS
RCE Exploit works on multiple Hosts
Default Credentials
Environment is broken