Earlier quoted context omitted.
How do you define a 'sandboxed' system? What if I choose to run the Wordpress/Django/Drupal/Whatever-CMS on a shared host? Cracking tools don't often take into account the negative effects on non-target hosts, nor are they generally tolerated by shell providers. For example, see 'Prohibited Usage' for Linode: https://www.linode.com/tos.cfm Unless you're paying for raw bandwidth, you're subject to the ToS of each reso…
Hmm. I think my confusion comes from the assumption that each "fortress" (server) is a virtual server hosted by ctf365. From their rules: Don't try to conduct underground activities with your Fortress (system) from our platform in the Real World (e.g. using our platform to spam others, attack other servers on the internet and so on). We don't care who you are, but we do care what you are doing in our home (CTF365 Pla…
Capture the flag 2013
51–55 of 55 posts
Re: Capture the flag 2013
#52Earlier quoted context omitted.
Ah, I suppose that would cover most bases. If they own the servers and they are giving permission to access them in such a way then there's likely no worries over unauthorized access type laws.
I took a look at this a while back (excited to see it's still going), but there is the chance that your ISP might send you a nastygram/suspend service if they notice a lot of activity that looks like port scanning, though that depends on how intrusive/vigilant your ISP is being.
Re: Capture the flag 2013
#53The apparent trouble with signup notwithstanding, this seems like great fun. The thing is, I didn't find out about those problems, because I didn't even try to sign up. I have no idea how I would go about getting started being able to do this. Can anybody suggest resources for lowly web developers to make our way into security? Even if just for fun?
Re: Capture the flag 2013
#54Interestingly, they're using the same technique for the cloud effect as that Japanese energy drink site that was posted here not too long ago.
Re: Capture the flag 2013
#55Tried to sign up and got the same message no matter what email/password I use: " Invalid email or password. "