← All talks

CTF Winners Announcement

BSides TLV · 201810:1188 viewsPublished 2018-07Watch on YouTube ↗
Speakers
About this talk
CTF Winners Announcment - Guy Barnhart-Magen BSidesTLV 2018 - Tel Aviv University - 19 June 2018
Show transcript [en]

how many over here try this again do you love it was it one of the best ETFs ever possibly the best CTF in the galaxy let's hear it from guy test us amazing co-organizer this year and CPF please

okay thank you very much I hope you can hear me we had a pretty amazing CBF this year and I want to do a couple of things and then the end and he acknowledged the winners I'm saying I'm not the only one saying that is probably one of the best ETFs in Israel and it was amazing out of several different aspects we had nine different members on the city F team I'll go through the names a bit later so you know who to blame for their favorite miss challenge we ran somewhere between three to five different servers just to keep everybody up and happy and who still had crashes we had 19 different challenges in total

ranging from something ridiculously easy to something outrageous ly hard and we spread out the challenges over two weeks more or less with new challenges being added every other day on average Sundays to Wednesday's to 30 days more or less so we can give people enough time to go over the challenges and rack the points this was not the regular city effort you have 48 hours to finish as many challenges that you can it was all a more like a city of Marathon where you had to crack the most difficult challenges in order to get those points and possibly get to the end of the winner so first of all we love feedback come find us come talk to us tell us how

the CDF went how we felt about it this little shiny medal each member of the CTF team is wearing one so you know exactly who to capture in a very dark corner but let us know what you felt about it I just want to share quickly a couple of the different feedbacks that we received a over the CBF some of them are in Hebrew some of them are in English we will do write-ups or works easily we will share those right up I do want to take time to point out that this specific challenge WTF lol I will not spell it out for you it was especially hard and we had some issues with it I'll come back to it later and

we were very happy they had a lot of people found the challenge of themselves well challenging or at least something that would keep them up at night trying to get the next flag sometimes there are more than one flag and specifically some of the people playing games there for God that we're actually running the servers so they started chatting with each other each other over /dev / TTY forgetting that we're owning the server and actually looking at what they're doing they started chatting and started to share information over the server that was pretty funny and you know it was very fun to write very fun to run and very fun to host it but in the end

what we care about is that we created something that brings the community together and brings people an opportunity to play in a high order game a capture the flag in the end is just a game you've solved the riddles you get the flag you capture the points this is it and we love the feedback and I do want to give a lot of credit to the team who built it and a lot of credit to the teams that spent so many hours trying to solve that CDF and specifically to Thomas Wright who

former more than anyone else has spit blood has sweated tears to get that City off of the ground and I want to show you a bit of what happened behind the scenes we had a lot of challenges without a lot of obscure names a lot of interesting things that went behind the scenes so I wrote them down so it would be very obvious to all of you who you need to blame for each of your pains and some of these challenges were ridiculously easy I'm in charge of one of the most ridiculous challenges ever so that was 50 points and if somebody hasn't tried it out you showed it to take you like one minute and we also

encountered some funny things along the way like having challenges building them out thinking that they're going to be extremely hard and then some hackers finding a different way to do it in under two hours that was really disappointing so but we learn from it and we try to improve ourselves and the challenges for the rest we also had an issue with one of our challenges where a flag was leaked and shared and we handled it as best we could transparently and in general we didn't want to hurt the capture the flag contest itself on the other hand we couldn't keep a challenge where a flag was freely shared over telegram and we didn't want to kick anybody out of the

contest as we believed that they did this as an honest mistake both the person who wrote the flag for his blog and the other person who saw the blog and god effect just wanted to test it out so we didn't disqualify anyone in the end this is just a game but it's something that we need to consider when we're playing this game to keep some of the rules at least we had a very dedicated SOC NIT teams that is Oh Mel and Tamela the kind of rhymes so Omar isn't here today unfortunately he's traveling somewhere over Vietnam I think at the moment but yeah that's we had 24-hour follow-the-sun IT service because when we were asleep Omer was

thinking things in Thailand timezone but in the end keeping the challenge running is a problem and but it's something that we need to do in order to get the game with low latency with responsive servers with non crashing docker services with servers that don't run out of Rams repeatedly and just to share some statistics we had 312 teams registered for the contest I think it's one of the most the the highest played CTF in Israel ever but when I looked at the data I didn't want to say just how many people signed up for the challenge I want to know how many people actually played the challenge and we had a hundred hundred twelve different teams

who solved at least one challenge so I think this is a beautiful turnout over a thousand different unique IP address to anybody thought we weren't looking at we were looking at them and just looking at the solve cons you can quickly see which was the easiest challenge over there and what was ridiculously hard this is the challenge that we canceled so these were ridiculously hard and some of them were just as hard as others and also that a lot of people were able to solve the more run-of-the-mill CTS but the more specialized CDF's took a lot more time now I want to discuss briefly the winners and again thank the CTF team for doing this for hosting this for helping

us thank you

keep it up you have to the speaker theme one of the most amazing city I've seen the galaxy I'm pretty sure they're okay who is the third place guy I'm not going to call everybody on state but I'm going to wave the prize and you can come to me afterwards so team J CTS speaker J is that the Jewish CTF yeah you want these amazing speakers very cool second place we have team baby roots you were amazing one of these are some things and coming now behind the scenes it is the biggest trophy you have ever seen crazy to end all trophies first place first of all the non herbal mention okay so Adam he's

a researcher for working for his Imperium actually won the first place but one of our rules and the reason for that world's we wanted to share with the community and he's based in Amsterdam and we have a rule that while we opened the contest for any remote team to play because we think it's fun you have to be present on stage to win the prize so all kudos to Adam for being unable to play the CDF but the first pressed first-place prize goes through reclass [Music] [Applause] can't get your trophy please guys don't forget to pose for the photo with the trophy come here is your photographer yay ooh TV class have you ever seen the trophy so big so

it up we are going to release the capture the flag as we believe in transparency in opening openness we're going to release the source code on github and Tomer has been kind enough to build a virtual machine to host on Vaughn hub that will be released as well please send us your write-ups if you have good write-ups we want to share them as well we believe in sharing the CDF of the how the CDF was constructed the infrastructure how do you select teams how do you select challenges we're going to renew a right upon that was well probably going to be released on a couple of different venues including digital whisper and in the end please

follow us come play again next year and take you all for playing [Applause]