Dear readers, Secnews in collaboration with the Master's Program in Digital Systems Security of the University of Piraeus, Department of Digital Systems, are organizing the second in a series of Secnews-Unipi Pwnzilla Challenge Attack!
For another year, the “PwnZilla” Web Hacking Challenge is a fact. Security experts in organizations and companies, as well as security researchers from academia (and not only), have been eagerly awaiting the announcement of PwnZilla 2, as we see daily from the e-mails sent to us.
Participants will have the opportunity to practice in a real, fully functional environment and evaluate the security of an information system that presents vulnerabilities. All known attacks can be carried out against the server that has been created for this very purpose (Sponsored by SecNews).

The main purpose of the exercise is to raise awareness and inform readers and Internet users on contemporary issues of security threats/attacks, as well as to practice their application of appropriate security assessment methods and tools without any legal consequences against them. This is a hacking game with the sole purpose of learning techniques and using advanced tools by the participants.
As in the first challenge (pz1) , the users' goals in this one are the following:
- Finding all the vulnerabilities found on the specific target website (https://pwnzilla.secnews.gr/).
- Exploiting these vulnerabilities and accessing the server.
- Drafting a relevant, extensive report detailing the manner in which the vulnerabilities were exploited.
- Identifying server vulnerabilities, if any.
Participants have 20 days to carry out the attacks!
So don't waste any time! Let the attacks begin NOW!
We invite researchers, security managers, security teams of institutions and organizations, as well as individuals who have security and vulnerability detection as a hobby, to immediately begin their testing to identify vulnerabilities at:
' PwnZilla Hacking Challenge 2 Terms & Conditions
- Participants can use any method they wish to gain access to the server and identify vulnerabilities.
- The use of DDoS and DoS techniques during the competition, which will lead to overloading of the information infrastructure, is not permitted.
- The grand winner of the Contest is the FIRST to send the COMPLETE SOLUTION of PwnZilla 2 , with all the identified vulnerabilities in an extensive analytical report .
- Upon completion of the tests, a special ceremony will be held at the University of Piraeus and a prize will be awarded to the grand winner.
- The competition will continue for 20 days even if the solution is found in the first few days.
- In the event that the solution is not found and the participants are unable to access the server, the prize will be awarded to one of the participants who has come closest to solving the problem.
- For your participation to be valid, you must provide your details in the form below (Note: pseudonyms can be provided instead of your real name if you wish).
- Reports & findings should be sent SIMULTANEOUSLY to the following emails: stasinopoulos[AT]unipi[DOT]gr and secnews[AT]secnews{DOT]gr
We invite you to complete the following participation form so that we can contact you if deemed appropriate regarding the competition:
[contact-form to='info@secnews.gr' subject='PwnZilla 2 Hacking Challenge'][contact-field label='Name/Nickname' type='name' required='1'/][contact-field label='Email' type='email' required='1'/][contact-field label='Website' type='url'/][contact-field label='Job/Profession' type='textarea'/][/contact-form]
The major sponsors
Major sponsors of the PwnZilla competition for 2015 are the Hosting company Host1Plus, which offers the prize for the grand winner, as well as the technology website iGuRu as a prominent communications sponsor.
The grand winner will win a VPS Platinum Plan package for a whole year, kindly sponsored by Host1Plus !!!
SecNews supports with its sponsorship the entire information infrastructure for the conduct of the security exercises, while the scientific responsibility lies with the Associate Professor of the University of Piraeus, Mr. Christos Xenakis , and the technical supervision with the Doctoral Candidate of the Department of Digital Systems, Mr. Anastasios Stasinopoulos .
The trainees who identify all the weaknesses - vulnerabilities of the system to be evaluated and manage to exploit them will be awarded at a special event to be held at the Systems Security Laboratory of the University of Piraeus.
Stay tuned in the coming days. The Secnews editorial team will make additional announcements during the Competition as well as exclusive statements from researchers & prominent figures in the field that will be discussed!
Hint: All vulnerabilities reported in the previous (pz1) challenge have been fixed.
[signoff icon=”icon-email”]Reports and findings should be sent SIMULTANEOUSLY to the following emails: stasinopoulos[AT]unipi[DOT]gr and secnews[AT]secnews{DOT]gr[/signoff]



