Skip to content

Welcome to KringleCon 5: Golden Rings!

Introduction

Welcome reader, to my 2022 SANS Holiday Hack Challenge Solution Guide. I'm Nutmeg, and this is my fifth year attending KringleCon.

First off, as always, I want to thank Ed Skoudis, the Counter Hack team, and all of the great KringleCon presenters. Once again, the team did a fantastic job producing an event that was both entertaining and educational.

I also want to thank my wife Kim, who once again resigned herself as a 'KringleCon Widow' for several weeks during the holiday season while I indulged myself in this event.

Lastly, and in no particular order, I want to acknowledge the following individuals from the Discord channel, without whose help I might still be bashing my head against the wall with Glamtariel's Fountain.

  • Annah
  • bsleep
  • higgy
  • Fogez
  • t4r
  • human

Report Format

This report is written as a guide to explain how I was able to solve each of the objectives. I make no assertion that the methods I used are the best or most effective, or even if they are how the designer of the objective intended it to be solved (Open the Boria Mine Door). Many objectives will have more than one way to complete them, and for some I have included several of the possible options (Windows Event Logs, Prison Escape), but this is by no means the case for every objective.

As this is a guide and not a full walk through of KringleCon, and to keep the length to something resembling the 50 page maximum submission size, I have omitted much of the character dialogs, story elements, LoTR references, etc. that are not directly related to the solving of objectives. Dialogs, hints, and other resources are in in expandable call-outs to keep the page lengths down, and all answer values are similarly hidden by default for those readers who are just looking for hints and don't want to see spoilers.

This writeup is also not as dependent on screenshots as my submissions in previous years have been, again in an attempt to keep the length as efficient as possible.

Platform and Tools

The majority of the objectives were completed on an Intel based PC running Windows 11 Home, and the primary web browser used was Firefox.

Wireshark and Burp Suite Community Edition were used in some way or another for many of the challenges.

The writeup itself was created using Material for MkDocs and is hosted on GitHub Pages. Any necessary screenshots were taken using ShareX, and code / writeup editing was done with Visual Studio Code.