
Intermediate75 min5 objectives
Database Encryption at Rest & in Transit
Implement transparent data encryption, column-level encryption, and TLS for database connections.
Briefing
### Scenario
You are a general practitioner handling a realistic client engagement. For Database Encryption at Rest & in Transit, the client has provided a staging environment that mirrors production but is isolated to this lab. Your task is to demonstrate the core technique on the local target without touching external systems. The scenario is intentionally scoped to what you can verify inside the container.
### Environment and scope
Use the Ubuntu 22.04 practice container. Working directory is `/home/student/lab-work` (create it with `mkdir -p`). Target is `127.0.0.1` and `127.0.0.1:8080` where a `python3 -m http.server` or service-specific daemon runs. Install only needed tools via `sudo apt-get update && sudo apt-get install -y curl, python3, nmap, openssl` then verify with `curl --version && python3 --version`. Credentials: `student:lab123` with `sudo` (created via `useradd` + `chpasswd` + `sudoers.d` as in `labs.service.ts:554`). Do not scan or query outside 127.0.0.0/8 or lab-work. Scope is strictly container-only; no external cloud, hardware, or nested container engines.
### Mission objective
For Database Encryption at Rest & in Transit: install and verify tooling, prepare the local target (`127.0.0.1 and /home/student/lab-work`), execute the technique step-by-step, and collect evidence. Each walkthrough step produces a verifiable artifact (file, command output, or service state) that you will cite in your submission.
### Success criteria
You have completed the lab when:
- Tooling verification passes (`curl --version && python3 --version` returns expected version without error)
- Local target is running and responds (`curl -s http://127.0.0.1:8080/` or `dig @127.0.0.1` or `tshark -r` shows expected output)
- `solution.md` in `lab-work` documents each step's exact command, raw output excerpt, and your interpretation (what the output proves)
- All flag answers are direct values from your local output (e.g., version string, status code, IP, header name) and no external hosts were targeted (`history | grep -E "nmap|dig|tshark|openssl|nikto|curl"` shows only 127.0.0.1)
Runtime mode: portable artifact validation
Objectives
- 1Prepare workspace and verify tooling
- 2Prepare local target for Database Encryption at Rest & in Transit
- 3Execute Database Encryption at Rest & in Transit technique
- 4Capture evidence
- 5Complete Crypto Enabler
- 6Complete Column Encryptor
- 7Tune and interpret
- 8Compile and verify submission
Flags
Crypto Enabler+100 pts
Submit the single keyword indicating success for Crypto Enabler (e.g., running, OK, enabled) from local tool output.
Column Encryptor+200 pts
Submit the verifiable output value for Column Encryptor as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Column Decryptor+200 pts
Submit the verifiable output value for Column Decryptor as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
SSL Configurator+200 pts
Submit the single keyword indicating success for SSL Configurator (e.g., running, OK, enabled) from local tool output.
SSL Verifier+150 pts
Submit the verifiable output value for SSL Verifier as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).