[Ended] Round 14 | Technical Document Scavenger Hunt
  

Sangfor Jojo Lv5Posted 2024-Dec-10 09:30


Dear members,
We are excited to announce the launch of our Technical Document Scavenger Hunt! This activity encourages all users to dive deeper into our newly published technical document in the Knowledge Base, enhancing your understanding and engagement with the material.

By participating, you'll sharpen your skills and have the chance to collaborate and share insights with fellow users. Happy hunting, and may the best reader win!


1. Activity Rules                                                                                                                     

1)  All community users are invited to participate in the scavenger hunt.
2)  There will be at least 6 questions related to the provided documents.
3)  Participants must submit their answers under this post by Dec. 16.
4)  Winners will be announced next Tuesday on the community platform.


2. Activity Duration                                                                                                               

Dec. 10 - Dec. 16

3. How to Participate                                                                                                                                                                                                                
1) Browse the Questions:
We have provided a list of questions based on the document\'s content. Your goal is to find the
answers within the documents.

2) Read the Documents:
Start by simply reading the catalog. Taking your second reading thoroughly with the given questions
which will make you read more efficiently.

3) Use the Search Function:
Most documents have a search feature. Use keywords from the questions to locate them quickly in relevant sections.

4) Submit Your Answers:
Once you have your answers, post them under this thread by the deadline.

5) Collaborate:
Feel free to discuss your findings in the forum and win 100 coins. Sharing thoughts and interpretations can lead to a deeper understanding and may help others in their search.



4.  Rewards                                                                                                                             

1) Correct Answers: 100 coins for each correct answer.
2) All Correct: An additional 100 coins for those who answer all questions correctly.
3) Users participating in this event for four consecutive weeks will receive an extra 400 coins. (NEW)
4) The top 3 users with the highest accuracy in answering questions for a month will earn an extra 400 coins. (NEW)
In short, you can get 400 to 1500 coins if you participate in the event every week.

5. Scavenger Hunt Questions                                                                                             

Read these documents on the left side and answer the questions below.

Sangfor HCI environment mirror external traffic to STAQ1: What are the version requirements for mirroring external traffic to vSTA in the Sangfor HCI environment?
Q2: What are the requirements of switch mirroring configuration guide - Huawei?
Sangfor Cyber Command How to analyze security threats Q3: What types of attacks are discussed in the document?
Q4: How to detect the phishing email based on this document?
Sangfor VDI Upgrade Guide_5.9.1R2_ENQ5: Which versions can be upgraded to VDI 5.9.1R2_EN?  (read the first 11 pages)
Q6: What change has been made to the VDC licensing mode starting from version 5.6.0_EN?  (read the first 11 pages)
Q7: What should users do if they upgrade from a version earlier than 5.6.0_EN to 5.9.1R2_EN? (read the first 11 pages)



6. How to Reply This Post                                                                                                   

Try to make it simple! Do not repeat the questions when typing your answers.

--------------------------------------------------------------------------------------------------------------------------------------
Sangfor Jojo Lv5Posted 2024-Dec-10 09:35
  
Congratulations to the following participants on getting the coin rewards.


CLELUQMAN Lv4Posted 2024-Dec-10 10:59
  
Q1 :   -HCI: Version 6.10.0R1+ custom patch.
        -SCP: only 6.10.0R1 version+ custom patch
        -vSTA: No restrictions. Can be installed in HCI environments.
        -Physical Switch: can mirror traffic to HCI physical interface.

Q2 :   -Configure GigabitEthernet0/0/1 as the mirror interface
        -GigabitEthernet0/0/2 as the observing interface
        -observing interface index number is 1
        -Mirror the bidirectional service traffic on GigabitEthernet0/0/1 to GigabitEthernet0/0/2

Q3 :  -Pre-attack
        -Mid-attack
        -Post-attack

Q4 :  -Phishing emails typically contain malicious links or files, luring users to click on them. You can download the malicious file

Q5 :  -5.5.0_EN, 5.5.6_EN, 5.6.0_EN ,5.9.0_EN, 5.9.1_EN, and 5.9.1R1_EN

Q6 :        -switched from licensing via USB-KEY to Platform-X licensing or SCP licensing

Q7 :        -need to complete the return and exchange process for the existing license within 30 days,
Newbie517762 Lv5Posted 2024-Dec-10 11:36
  
Q1. - HCI: only 6.10.0R1 version+ custom patch
       - SCP: only 6.10.0R1 version+ custom patch (If an SCP exists, it requires a patch; otherwise, it can be ignored).

Q2. Configure GigabitEthernet0/0/1 as the mirror interface, GigabitEthernet0/0/2 as the observing interface, and the observing interface index number is 1. Mirror the bidirectional service traffic on GigabitEthernet0/0/1 to GigabitEthernet0/0/2.

Q3. Pre-attack, Mid-attack & Post-attack detection and analysis.

Q4. Phishing emails typically contain malicious links or files, luring users to click on them.

Q5. Only the official versions, including 5.5.0_EN, 5.5.6_EN, 5.6.0_EN ,5.9.0_EN, 5.9.1_EN, and 5.9.1R1_EN, can be upgraded to VDI 5.9.1R2_EN.

Q6. Starting from 5.6.0_EN, the virtualization platform is switched from VMP to HCI, and the sales device HCI uses vKEY instead of USB-KEY. After you upgrade a version earlier than 5.6.0_EN to 5.9.1R2_EN, the previous
license of the virtualization platform will become invalid. Sangfor will provide a 30-day grace period to ensure that the existing business is not affected. In this case, you need to complete the return and exchange process for the existing license within 30 days, switch the licensing mode to vKEY licensing, and complete relicensing.

Q7. For versions earlier than 5.6.0_EN (excluding 5.5.0_EN and 5.5.6_EN), you need to upgrade the versions to 5.5.6_EN and then to 5.9.1R2_EN. The iteration and restart of multiple versions are involved, so it takes a long
time and the whole process may need to be split into multiple phases.
Humayun Ahmed Lv3Posted 2024-Dec-10 12:29
  
Q1: HCI: Only version 6.10.0R1 with a custom patch is supported.
SCP: Only version 6.10.0R1 with a custom patch (if an SCP exists; if not, this can be ignored).
vSTA: There are no restrictions, and it can be installed in HCI environments.
Physical Switch: It must be able to mirror traffic to the HCI physical interface.

Q2: Configure GigabitEthernet0/0/1 as the mirror interface.
Configure GigabitEthernet0/0/2 as the observing interface, with the observing interface index number set to 1.
Mirror the bidirectional service traffic from GigabitEthernet0/0/1 to GigabitEthernet0/0/2.

Q3: Information Disclosure
Remote Code Execution Vulnerabilities
Apache Struts OGNL Expression Injection Vulnerability
ExifTool Code Execution Vulnerability
General System Command Injection
General SQL Injection Attack
Brute Force Exploits (SSH, MySQL)
Phishing emails
Cross-Site Scripting (XSS) attacks
WebShell attacks
Infiltration attempts
Cobalt Strike backdoor
Reverse Shell

Q4: Look for Malicious Links or Files: Phishing emails typically contain links or files that lure users to click on them.
Download the Malicious File: If you suspect an email is a phishing attempt, download the attached files.
Use VirusTotal: Upload the downloaded malicious file to www.virustotal.com to analyze it for potential threats.
Beware of Tampered Email Addresses: Note that the sender's email address may be tampered with to appear legitimate. Thus, it should not solely be relied upon to assess the email's authenticity.

Q5: VDI 5.5.0_EN
VDI 5.5.6_EN
VDI 5.6.0_EN
VDI 5.9.0_EN
VDI 5.9.1_EN
VDI 5.9.1R1_EN
For other versions, you need to upgrade them to VDI 5.5.6_EN first before proceeding to VDI 5.9.1R2_EN.

Q6: Starting from version 5.6.0_EN, the VDC licensing mode has changed from licensing via USB-KEY to either Platform-X licensing or SCP licensing. This means that the previous method using USB-KEY is no longer supported. After upgrading from a version earlier than 5.6.0_EN to 5.9.1R2_EN, the previous license will become invalid, and users will need to switch to the new licensing modes and complete the relicensing process within a 30-day grace period.

Q7: Upgrade to 5.5.6_EN first: Users must upgrade to version 5.5.6_EN before upgrading to 5.9.1R2_EN.
Deletion of Incompatible Features: If the version being upgraded includes features incompatible with 5.9.1R2_EN, users need to delete these features prior to the upgrade.
Pre-Upgrade Check: It’s recommended to perform a pre-upgrade check using aDesk Tools to ensure that the environment and requirements are met.
Licensing Changes: After the upgrade, the previous license will become invalid. Users will need to switch to the new licensing modes (Platform-X or SCP licensing) and complete the relicensing process within a 30-day grace period.
Notify Users: It’s advisable to notify all users about the upgrade plans, as the upgrade will cause logged-in users to disconnect and VMs to restart.
Enrico Vanzetto Lv4Posted 2024-Dec-10 15:59
  
Q1:HCI: only 6.10.0R1 version+ custom patch SCP: only 6.10.0R1 version+ custom patch (If an SCP exists, it requires a patch; otherwise, it can be ignored). vSTA: No restrictions. Can be installed in HCI environments. Physical Switch: can mirror traffic to HCI physical interface.
Q2:Configure GigabitEthernet0/0/1 as the mirror interface, GigabitEthernet0/0/2 as the observing interface, and the observing interface index number is 1. Mirror the bidirectional service traffic on GigabitEthernet0/0/1 to GigabitEthernet0/0/2.
Q3:pre-attack, mid-attack,post-attack,infiltration and c&c
Q4:Submit hte attachmento to virustotal to check if it's secure
Q5:Only the official versions, including 5.5.0_EN, 5.5.6_EN, 5.6.0_EN ,5.9.0_EN, 5.9.1_EN, and 5.9.1R1_EN, can be upgraded to VDI 5.9.1R2_EN.To upgrade other versions to VDI 5.9.1R2_EN, you must upgrade them to 5.5.6_EN first.
Q6:Starting from 5.6.0_EN, the VDC licensing mode is switched from licensing via USB-KEY to Platform-X licensing or SCP licensing. That is, the licensing method using USB-KEY is no longer supported. After you upgrade a version earlier than 5.6.0_EN to 5.9.1R2_EN, the previous license will become invalid. Sangfor will provide a 30-day grace period to ensure that the existing business is not affected. In this case, you need to complete the return and exchange process for the existing license within 30 days, switch the licensing mode to Platform-X licensing or SCP licensing, and complete relicensing.
Q7:To upgrade other versions to VDI 5.9.1R2_EN, you must upgrade them to 5.5.6_EN first.
Newbie362074 Lv3Posted 2024-Dec-10 16:09
  
Q1: only 6.10.0R1 version+ custom patch
Q2: Configure GigabitEthernet0/0/1 as the mirror interface,
GigabitEthernet0/0/2 as the observing interface, and the observing interface index
number is 1. Mirror the bidirectional service traffic on GigabitEthernet0/0/1 to
GigabitEthernet0/0/2
Q3: Pre-attack, Mid-attack, post-attack
Q4:  malicious links or files
Q5: official versions, including 5.5.0_EN, 5.5.6_EN, 5.6.0_EN ,5.9.0_EN, 5.9.1_EN, and 5.9.1R1_EN
Q6: switched from licensing via USB-KEY to Platform-X licensing or SCP licensing
Q7: need to purchase complete HCI licenses
ND Lv3Posted 2024-Dec-10 16:28
  
Q1: only 6.10.0R1 version+ custom patch

Q2: Configure GigabitEthernet0/0/1 as the mirror interface, GigabitEthernet0/0/2 as the observing interface, and the observing interface index number is 1. Mirror the bidirectional service traffic on GigabitEthernet0/0/1 to GigabitEthernet0/0/2.

Q3: Pre-attack, mid-attack and post-attack

Q4: download the malicious file. Unzip and get the malicious file. Upload this malicious file to www.virustotal.com

Q5: Only the official versions, including 5.5.0_EN, 5.5.6_EN, 5.6.0_EN ,5.9.0_EN, 5.9.1_EN, and 5.9.1R1_EN, can be upgraded to VDI 5.9.1R2_EN.
To upgrade other versions to VDI 5.9.1R2_EN, you must upgrade them to 5.5.6_EN first.

Q6: the VDC licensing mode is switched from licensing via USB-KEY to Platform-X licensing or SCP licensing.

Q7: , you need to complete the return and exchange process for the existing license within 30 days, switch the licensing mode to vKEY licensing, and complete relicensing.
Farina Ahmed Lv5Posted 2024-Dec-10 17:17
  
Q1. Physical traffic mirroring to vSTA - Applicable to HCI6.10.0.R1.
Q2. Switch mirroring configuration guide - Huawei
Requirements: Configure GigabitEthernet0/0/1 as the mirror interface,
GigabitEthernet0/0/2 as the observing interface, and the observing interface index
number is 1. Mirror the bidirectional service traffic on GigabitEthernet0/0/1 to
GigabitEthernet0/0/2.

Q3. XSS attack, WebShell attack, SQL injection attack

Q4. Phishing emails typically contain malicious links or files, luring users to click on
them. You can download the malicious file. Unzip and get the malicious file. Upload this malicious file to www.virustotal.com

Q5. Only the official versions, including 5.5.0_EN, 5.5.6_EN, 5.6.0_EN ,5.9.0_EN, 5.9.1_EN, and 5.9.1R1_EN, can be upgraded to VDI 5.9.1R2_EN.

Q6. Starting from 5.6.0_EN, the VDC licensing mode is switched from licensing via USB-KEY to Platform-X licensing or SCP licensing. That is, the licensing method using USB-KEY is no longer supported. After you upgrade a version earlier than 5.6.0_EN to 5.9.1R2_EN, the previous license will become invalid. Sangfor will provide a 30-day grace period to ensure that the existing business is not affected.

Q7. Starting from 5.6.0_EN, the virtualization platform is switched from VMP to HCI, and the sales device HCI uses vKEY instead of USB-KEY. After you upgrade a version earlier than 5.6.0_EN to 5.9.1R2_EN, the previous license of the virtualization platform will become invalid.


Clarence Roque Lv2Posted 2024-Dec-11 09:31
  
Q1: 6.10.0R1 version+ custom patch
Q2: Configure GigabitEthernet0/0/1 as the mirror interface, GigabitEthernet0/0/2 as the observing interface, and the observing interface index number is 1. Mirror the bidirectional service traffic on GigabitEthernet0/0/1 to GigabitEthernet0/0/2.
Q3: Pre-Attack Risks:
Weak passwords (Telnet, web)
Plaintext transmission

Mid-Attack Detection:
Information disclosure
Remote code execution (e.g., Apache Struts, ExifTool)
SQL injection
Brute force attacks (SSH, MySQL)
Phishing emails
XSS (Cross-Site Scripting)
WebShell attacks

Post-Attack Detection:
Malware (e.g., virus files, WebShells)
Infiltration (e.g., Cobalt Strike, reverse shell, command injection)
Command and Control (C&C) activities (e.g., DNS tunneling, malicious domains, worm infections)

Q4: download the malicious file, Unzip and get the malicious file, Upload this malicious file to www.virustotal.com
Q5: 5.5.0_EN, 5.5.6_EN, 5.6.0_EN ,5.9.0_EN, 5.9.1_EN, and 5.9.1R1_EN
Q6: need to determine the licensing mode to be used in the future based on the usage scenarios and request the responsible sales representative to initiate a return or exchange process for the existing license.
Q7: 1. Upgrade to 5.5.6_EN first, as versions earlier than 5.6.0_EN cannot upgrade directly to 5.9.1R2_EN.
2. Perform pre-upgrade checks using aDesk Tools to ensure compatibility and address any issues.
3. Switch licensing mode:
* For VDC: Move to Platform-X licensing or SCP licensing.
* For HCI: Use vKEY licensing.
4. Merge base images if needed, during non-business hours to avoid disruptions.
5. Complete the upgrade to 5.9.1R2_EN:
* Shut down all VMs.
* Upgrade VMP, HCI, and VDC as instructed.
6. Post-upgrade:
* Verify that all systems are running smoothly.
* Manually update VM agents for nonpersistent templates.