Live data from Hacker News

Capture the flag 2013

ctf365.com

41–50 of 55 posts

Re: Capture the flag 2013

#43
post #36

Earlier quoted context omitted.

Ah, I suppose that would cover most bases. If they own the servers and they are giving permission to access them in such a way then there's likely no worries over unauthorized access type laws.

I took a look at this a while back (excited to see it's still going), but there is the chance that your ISP might send you a nastygram/suspend service if they notice a lot of activity that looks like port scanning, though that depends on how intrusive/vigilant your ISP is being.

If ctf365 wanted to keep the playing field level, they could sandbox the entire network so that attacks originate from another device on the network. So you have:

  -----------------Network-----------------------------------
  my_fortress  competitors_fortress
  -----------------------------------------------------------
No shady traffic ever needs to traverse the public internet. Only ssh access to my_command&control_box and my_fortress is required. This has the added benefit of normalizing the attacking horsepower of the entrants.

Re: Capture the flag 2013

#45
post #26

Interestingly, they're using the same technique for the cloud effect as that Japanese energy drink site that was posted here not too long ago.

I hope their use of imagery from the Captain America movie is covered under fair use or derivative work. http://comicbookmarks.com/wp-content/uploads/2011/08/detail-...

Agreed!

Re: Capture the flag 2013

#47

Anyone interested in making a HN team? (possibly a few given that it's limited members/team)

I'd be interested in joining one if there is space for someone with limited administration experience.

Shoot me an email, brianw.stearns@gmail.com. I have [very] limited practical admin experience, but I will try to scare up a friend who can devote some time to it.

Re: Capture the flag 2013

#48

Earlier quoted context omitted.

I took a look at this a while back (excited to see it's still going), but there is the chance that your ISP might send you a nastygram/suspend service if they notice a lot of activity that looks like port scanning, though that depends on how intrusive/vigilant your ISP is being.

If ctf365 wanted to keep the playing field level, they could sandbox the entire network so that attacks originate from another device on the network. So you have: -----------------Network----------------------------------- my_fortress competitors_fortress ----------------------------------------------------------- No shady traffic ever needs to traverse the public internet. Only ssh access to my_command&control_box a…

That would limit to some degree the gear that you could bring to the fight. Given that choice of tools in this situation is a valid differentiator I don't think arranging the challenge as "Backtrack5 at Dawn" is a realistic way to go about it. Clearly you could write or upload anything you wished if you sshed in, but the added convenience of BYOD seems like a net win.

Re: Capture the flag 2013

#49
CTF365 It's a Startup on bootstrap mode (self funded) that will change the way Information Security is learned. We try to do our best with very few resources. No seed money, no Kickstarter money but full of passion and dedication.

Re: Capture the flag 2013

#50
post #10

This will be interesting to see when finished, but it would be better if each 'Fortress" had to offer services, instead of dictating that each camp has to run POP + Wordpress + some bullshit plugins. Also, this type of activity definitely will break terms of service for internet service and hosting providers, as well as potentially several laws.

We want to make as few rules as possible. Our scope is to mimic the real world. Still working on the game design and mechanics.
Post reply on HN