Skip to content

Site Takeover: diskless Live USB beginner lab - #1

Draft
skjshr wants to merge 5 commits into
mainfrom
feat/live-usb-b2r
Draft

Site Takeover: diskless Live USB beginner lab#1
skjshr wants to merge 5 commits into
mainfrom
feat/live-usb-b2r

Conversation

@skjshr

@skjshr skjshr commented Jul 27, 2026

Copy link
Copy Markdown
Owner

Start here

Both links require access to this private repository. The participant-facing guide remains inside the target and does not expose the operator solution.

Outcome

Adds the current Site Takeover Live USB lab for an isolated, authorized beginner workshop while preserving the target laptop's Windows installation and internal SSD.

The company target Windows PC, one USB, and a personal internet connection are sufficient to download and verify the prepared files and attempt USB creation. Actual readiness still depends on the physical USB, target laptop, isolated Kali, and Windows/BitLocker return gates listed below.

What changed

  • Adds the café target, staged participant guide, required homepage takeover, and optional private-note/root bonuses.
  • Publishes one canonical METHODS guide covering company setup, USB, target boot, Kali, the complete required exploit, root bonus, reset, recovery, verification, and troubleshooting.
  • Packages the complete hierarchy as a checksummed operator-kit ZIP so every relative link works after a clean company download.
  • Builds a Debian 13 toram nopersistence Live ISO with BIOS/UEFI Secure Boot entries.
  • Fails closed unless the Live medium is RAM-backed, no physical disk is visible, and only the direct Ethernet lab network is active.
  • Adds temporary maintenance-only Codex, USB qualification, bare-metal/VirtualBox Kali isolation, and day-of runbooks.
  • Adds CI and a draft-prerelease workflow with build/release token separation and same-commit operator-kit packaging.

Evidence

  • Node tests: 22/22 pass
  • Bash syntax: 11 scripts pass
  • PHP lint: 4/4 pass
  • PowerShell parse/bootstrap self-test: pass
  • Workflow YAML and 9 embedded Bash blocks: pass
  • Firefox full participant flow: pass at desktop and 360px; no horizontal overflow at 360/1280/1366
  • Exact ISO: SHA-256 f6d5abfe122aa9f32a19001390ff9d312b26417aa3ae2f18fe2b352e68fc337f; BIOS/UEFI present
  • Exact ISO re-downloaded from the draft release with the same SHA-256
  • Diskless exact-ISO VM: 22/22 preflight pass, attack flow pass, reboot reset pass
  • Operator kit: clean GitHub re-download, SHA-256 809d2e291df06a5d6e9695c19a5984c2ffeacf5d781561dcf963335e58f94051, 16 relative links resolve, extracted bootstrap self-test pass

See labs/site-takeover/VERIFICATION.md for the evidence boundary.

Draft prerelease provenance

site-takeover-live-v0.1.0-rc1 remains draft + prerelease and unpublished.

  • ISO source commit: b7b9acaa7df430aa92a7447e4ba244d6bc9a6d11
  • Operator-method source commit: 9998a943ba6df8d4a0a418a9a3eaf3261ca66da5

The second commit changes documentation, release packaging, and tests. It is not claimed to be embedded in the ISO; the ISO retains its independently verified b7b9aca metadata.

GitHub-hosted jobs currently stop before step 1 because the account reports a payment/spending-limit gate. The exact ISO was therefore rebuilt from the clean ISO source commit on the verified Debian 13 VM. An Actions-produced ISO remains a separate external gate.

Physical gates still open

  • Replacement or BUFFALO USB full-capacity H2testw Write + Verify with zero errors
  • Target laptop USB boot, RAM-media confirmation, SSD invisibility, and USB removal
  • Borrowed Kali or isolated Kali-VM preflight
  • Windows/BitLocker return check

Do not merge or publish the draft release until those physical gates are recorded.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant