A Brief Intro to CTF Contests!

15
CAPTURING THE FLAG shabgard

Transcript of A Brief Intro to CTF Contests!

Page 1: A Brief Intro to CTF Contests!

CAPTURING THE FLAG

shabgard

Page 2: A Brief Intro to CTF Contests!

How are we?

▪ Geek AsiralShabgard ?

Mormoroth(Not in our team)

Page 3: A Brief Intro to CTF Contests!

What is CTF?

▪ Capture the Flag (CTF) is a special kind of information security competitions.

▪ Two common types of CTFs: Jeopardy, Attack-Defence.– Jeopardy-style CTFs has a couple of questions (tasks) in range

of categories. For example, Web, Forensic, Crypto, Binary or something else.

– Attack-defence is another interesting kind of competitions. Here every team has own network(or only one host) with vulnarable services. Your team has time for patching your services and developing exploits usually.

Page 4: A Brief Intro to CTF Contests!

Flag?

▪ Hidden somewhere

▪ Usually in hex

Page 5: A Brief Intro to CTF Contests!
Page 6: A Brief Intro to CTF Contests!
Page 8: A Brief Intro to CTF Contests!

Jeoperdy style task

▪ Pwning/Exploiting

▪ Reverse engineering

▪ Web hacking

▪ Crypto

▪ Secure coding

▪ Stegano

▪ Forensics

▪ Recon

▪ Social engineering

▪ Trivia

Page 9: A Brief Intro to CTF Contests!

Atack-defence

Page 10: A Brief Intro to CTF Contests!

Famous CTFs

▪ DEFCON– Jeopardy + Attack-defence

▪ CCAW (NYU– Jeopardy

▪ ICTF (UCSB)– Jeopardy + Attack-defence

Page 11: A Brief Intro to CTF Contests!

Famous Teams

▪ Geek of cource ;)

▪ Iranian teams:– ASIS– SUT– Noob– Baghali– UICERT

▪ Global– Plaid Parliament of Pwning

(US)– Dragon Sector (PO)– More Smoked Leet Chicken

(RU)– StratumAuhuur (DE)

Page 12: A Brief Intro to CTF Contests!

Tom croose

▪ George Hotz (1989)

▪ George competed alone in CSAW 2013 where he took first place competing alone under the pseudonym tomcr00se.

Page 13: A Brief Intro to CTF Contests!

Ingredients

▪ Security skills like exploiting, crypto, … (daa..)

▪ Scripting

▪ Teamwork – team size matters too

▪ Lot’s of coffee

Page 14: A Brief Intro to CTF Contests!

Where to start

▪ Online CTFs – CTFTime.org

▪ Past CTF archives– shell-storm.org/repo/CTF– capture.thefl.ag

▪ Read write-ups– CTFTime.org– Team’s blogs

▪ Sharif’s CTF wiki– wiki.ctfnews.com

▪ A great intro on DEFCON:– www.youtube.com/watch?

v=okPWY0FeUoU

Page 15: A Brief Intro to CTF Contests!

Thank You