Live data from Hacker News

An informal review of CTF abuse

gynvael.coldwind.pl

21–30 of 45 posts

Re: An informal review of CTF abuse

#21

>However there are stories of teams going a step further and hacking home routers from random IPs located in various countries. I guess that's trading in ethics and legality for CTF points. Is finding a single proxy in a country that hard that you need to do that? I would assume proxy lists including each country would already exist.

Basically the first 50 countries were easy using whatever methods. The next 50 were doable. But then the struggle really began and some teams started getting desperate/creative I guess.

Note that I'm using 50 as a random example number here, not an actual measurement.

Re: An informal review of CTF abuse

#22
post #7

>(or rather: fun factor after a couple of years passed and folks stopped being annoyed or down right furious at the perpetrators) Poor sports, I’ve always struggled to understand people who’d partake in hacking competitions and then get upset because someone got onto their computer and took all the flags.

> Poor sports, I’ve always struggled to understand people who’d partake in hacking competitions and then get upset because someone got onto their computer and took all the flags. The sport is about everyone racing to solve the same puzzles. If one team is sabotaging the puzzles in the process, it's a different kind of competition than the players expected. Frustration is warranted. It would be like signing up for the…

>it's a different kind of competition than the players expected

CTFs are (usually) hacking competitions for hackers, what else would you expect?

Re: An informal review of CTF abuse

#23
post #17

Earlier quoted context omitted.

Imma use that opportunity and ask Are skills of military/state-level actors comparable with CTF people? Or they're mostly focused on different things, so it's tricky to compare those things? I'm asking because it feels like at the end of the day all of those groups search for 0days

There is some overlap, but only some. In general CTF problems are limited in the sense that they need to be solvable withing the tournament time frame (usually 48h), and also the process is simpler - you don't have to be quiet, you grab the flag and that's it; no need to think beyond that point (i.e. no need to worry about backdooring, C2, hiding the traffic, lateral movement, detection, etc). Also CTF problems might…

Thank you

Re: An informal review of CTF abuse

#24
post #14

Earlier quoted context omitted.

Also the pandemic happened. In the later years we were playing mostly to go to offline finals. And the pandemic meant no offline finals.

Imma use that opportunity and ask Are skills of military/state-level actors comparable with CTF people? Or they're mostly focused on different things, so it's tricky to compare those things? I'm asking because it feels like at the end of the day all of those groups search for 0days

Also a lot of the time they are they can be the same people. Just one set of targets for your day job, one set of targets for fun at the CTF. (and the ctf challenges are probably easier)!

Re: An informal review of CTF abuse

#26
post #8

I've been playing shooters for almost 30 years now, and that includes a lot of CTF on top of tons of duel and TDM. Quake, UT, TF2 (just got back to it after a decade). That said, I have no idea what this guy is talking about. I thought he was talking about gaming but the more I read, the more confused I get. Especially the facebook part. What is going on here? edit: thanks, Retr0id

If you like that, HackFortress is a CTF that combined both sides, the video game playing and the hack style CTF. Looks like they're going to be back this year for defcon, I ran a team for several years.

I found it to be some of the most fun ctfs I played, partially because it was extremely time-bound. Rounds were 20 to 30 minutes each. It meant that you still had the rest of your conference time for other activities, rather than taking over your entire weekend.

Re: An informal review of CTF abuse

#27
post #7

>(or rather: fun factor after a couple of years passed and folks stopped being annoyed or down right furious at the perpetrators) Poor sports, I’ve always struggled to understand people who’d partake in hacking competitions and then get upset because someone got onto their computer and took all the flags.

"Poor sports, I've always struggled to understand people who'd partake in a foot race and then get upset because someone walked out of bounds to skip part of the race"

Simply because the context is hacking does not mean that performing additional hacking outside of the context of the competition is in the same spirit. Breaking the rules isn't hacking better than another team, it's breaking the rules.

Re: An informal review of CTF abuse

#28
post #22

Earlier quoted context omitted.

> Poor sports, I’ve always struggled to understand people who’d partake in hacking competitions and then get upset because someone got onto their computer and took all the flags. The sport is about everyone racing to solve the same puzzles. If one team is sabotaging the puzzles in the process, it's a different kind of competition than the players expected. Frustration is warranted. It would be like signing up for the…

>it's a different kind of competition than the players expected CTFs are (usually) hacking competitions for hackers, what else would you expect?

It's like saying in biathlon (skiing+shooting) how can you arrive at the finish second if you have a working gun?

Rules are rules, there's a clearly defined scope of where the fighting happens and where it does not.

Re: An informal review of CTF abuse

#29

What happened to author's team (Dragon Sector)? Until 2020 they were almost always around top3 and a few times top1 teams in the world according to https://ctftime.org/ but in 2021/2022 I don't see them

The first comment explains why they didn’t win one competition in 2014:

  2022-07-23 18:58:31 = -ENOCHEAT

  > I also saw once a player trying to swipe a piece of paper with configuration (user/password) details of another team on an Attack&Defense style CTF. They were caught in the act and their team got some penalty for it.

  We did exactly that at the Nuit du Hack CTF finals in 2014 to snatch the win against you folks (Dragon Sector). Since there was a flag specifically designed around shoulder surfing (taped to the network switch on each team's table) we asked organizers whether swiping the config credentials was fair game, and they said it was completely fine. Absurd, but hey, I don't make the rules :)

Re: An informal review of CTF abuse

#30

Would be nice if there was the briefest description about what CTF means here, since I expected it to be about gaming (ie Team Fortress) https://www.enisa.europa.eu/news/enisa-news/capture-the-flag...

As far as I understand it's competitive hacking/security which requires really solid theoretical knowledge and hands-on experience from various computer related topics like: cryptography, reverse engineering, web, low lvl programming, operating systems, networks, protocols, etc, etc. Top competitors tend to work at e.g Google for Project Zero or other big institutions like CERT ( https://en.wikipedia.org/wiki/Compute…

CTF is kind of like the security equivalent to what a cooking drama show (think Gordon Ramsey and a bunch of contestants) might be to being an actual chef.
Post reply on HN